Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Proofpoint PPAN01 Exam - Topic 3 Question 7 Discussion

Actual exam question for Proofpoint's PPAN01 exam
Question #: 7
Topic #: 3
[All PPAN01 Questions]

An analyst is reviewing the Notable Senders section in Proofpoint Supplier Threat Protection.

Based on the data shown in the exhibit, which vendor's email activity should be investigated first?

Show Suggested Answer Hide Answer
Suggested Answer: C

Supplier Threat Protection prioritization focuses on vendor identities whose messaging patterns indicate elevated risk---such as unusual sending behavior, higher malicious/suspicious message counts, abnormal spike patterns, or stronger impersonation/compromise indicators relative to other suppliers. Based on the exhibit's Notable Senders metrics, bob@aerowestglobalservices.com (C) shows the highest-risk activity and should be investigated first. In Proofpoint IR workflow, supplier-related threats are high impact because they exploit trust relationships and can bypass user suspicion (invoice/payment workflows, shared documents, ongoing threads). The investigation typically validates whether this is: (1) a compromised supplier mailbox, (2) supplier-domain impersonation (lookalike domain), or (3) a legitimate supplier system misconfigured and sending risky content. Analysts pivot into message samples, authentication alignment (SPF/DKIM/DMARC), sending infrastructure changes, and recipient targeting patterns (finance/AP, executives). If malicious, containment includes blocking the supplier sender/domain (or precise subdomains), pulling delivered copies via TRAP, alerting impacted users, and initiating vendor contact to remediate the supplier's account security.


Contribute your Thoughts:

0/2000 characters
Shelton
4 days ago
I feel like we had a similar question where we had to analyze patterns. I think it was about identifying unusual spikes in activity.
upvoted 0 times
...
Noel
9 days ago
I’m not entirely sure, but I remember a practice question where we had to consider the sender's reputation too. That might help here.
upvoted 0 times
...
Lyla
14 days ago
I think we discussed how to prioritize based on the volume of emails sent. Maybe we should look at the one with the highest number first?
upvoted 0 times
...

Save Cancel