A security analyst reviews a SIEM alert related to a suspicious email and wants to verify the authenticity of the message:
SPF = PASS
DKIM = FAIL
DMARC = FAIL
Which of the following did the analyst most likely discover?
Comprehensive and Detailed Step-by-Step The SPF = PASS result confirms the email came from an authorized server, but DKIM = FAIL indicates the message was not properly signed with the expected DomainKeys Identified Mail (DKIM) signature. DMARC = FAIL suggests that because DKIM failed, the overall email authentication failed. This scenario is consistent with a legitimate server sending an unsigned email.
CompTIA CySA+ All-in-One Guide (Chapter 5: Email Analysis)
CompTIA CySA+ Practice Tests (Domain 1.3 Email Authentication)
Bobbye
2 months agoKerry
8 days agoNguyet
27 days agoGarry
1 months agoAdell
1 months agoLeonida
2 months agoChaya
22 days agoQuiana
1 months agoLazaro
2 months agoTracey
2 months agoLauran
2 months agoMarva
2 months agoPearline
2 months agoTashia
2 months agoRosina
22 days agoChaya
1 months agoDahlia
1 months agoJamal
2 months agoDevora
2 months agoLavina
2 months ago