exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 116 discussion

Actual exam question from CompTIA's CS0-003
Question #: 116
Topic #: 1
[All CS0-003 Questions]

A security analyst must review a suspicious email to determine its legitimacy. Which of the following should be performed? (Choose two.)

  • A. Evaluate scoring fields, such as Spam Confidence Level and Bulk Complaint Level
  • B. Review the headers from the forwarded email
  • C. Examine the recipient address field
  • D. Review the Content-Type header
  • E. Evaluate the HELO or EHLO string of the connecting email server
  • F. Examine the SPF, DKIM, and DMARC fields from the original email
Show Suggested Answer Hide Answer
Suggested Answer: AF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kmordalv
Highly Voted 1 year, 7 months ago
Selected Answer: BF
Correct Review the headers from the forwarded email: Examining the email headers can provide crucial information about the email's source, path, and any intermediaries it went through. This information can help identify signs of spoofing or suspicious behavior. Examine the SPF, DKIM, and DMARC fields from the original email: These three mechanisms (Sender Policy Framework - SPF, DomainKeys Identified Mail - DKIM, and Domain-based Message Authentication, Reporting, and Conformance - DMARC) are used to authenticate the sender's domain and reduce the likelihood of email spoofing. Checking these fields can provide insights into the authenticity of the email.
upvoted 17 times
Robuste7
2 weeks, 1 day ago
I mean, why should we focus on the forwarded email? Because every time an email is forwarded, the new email creates a new envelop. That means we won't be able to see the old header,
upvoted 1 times
...
TurboMor
7 months, 2 weeks ago
ChatGPT is going to make you fail hehe... if you review the headers of the "forwarded" email, you are going to look at the details of the forwarded email, not the malicious email.
upvoted 10 times
...
...
greatsparta
Highly Voted 1 year, 4 months ago
Selected Answer: AF
I think B is a bit of a trick as reviewing the "forwarded" email headers would not provide accurate details of the original path. (unless it is forwarded as an attachment with the original email)
upvoted 16 times
...
f90ecff
Most Recent 1 week, 1 day ago
Selected Answer: AF
Chat GPT picked B until I pointed out that it was a forwarded email. Great catch — yes, the fact that it’s a forwarded email does matter and can change how useful the headers are.
upvoted 1 times
...
Comicbookman
1 month, 1 week ago
Selected Answer: AF
The two best options for determining the legitimacy of a suspicious email are: Evaluate scoring fields, such as Spam Confidence Level and Bulk Complaint Level (A) – These scores help determine if an email is likely spam or phishing based on predefined filters and reports. Examine the SPF, DKIM, and DMARC fields from the original email (F) – These authentication mechanisms verify whether the email was sent from an authorized source and ensure its integrity.
upvoted 1 times
...
DARKVEGETA
1 month, 3 weeks ago
Selected Answer: AF
Threat Analyst here. AF is correct. We are talking about a forwarded email. When my team get a spearphishing email we ALWAYS ask for the original email to be saved and sent to us so we can look at the headers. Forwarded emails will not have that information.
upvoted 2 times
...
7167087
3 months, 1 week ago
Selected Answer: AF
I think the key here is the assumption of a forwarded email. Forwarded email headers already cannot be useful for analysis, and still you have to focus on addressing the question. A is a general, direct answer of the question, while B is operating on assumptions not addressed in the question.
upvoted 1 times
...
luiiizsoares
4 months, 3 weeks ago
Selected Answer: BF
Correct Answers: B. Review the headers from the forwarded email F. Examine the SPF, DKIM, and DMARC fields from the original email Analysis: Review the headers from the forwarded email (B): Email headers contain important metadata, such as the sender’s IP address, email servers involved, and the path taken by the email. Reviewing headers helps in identifying spoofed addresses and abnormal routing paths. Examine the SPF, DKIM, and DMARC fields from the original email (F): These fields help validate the authenticity of the email. SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting & Conformance) are email authentication protocols used to verify that the email was indeed sent from the claimed domain and was not altered in transit.
upvoted 1 times
...
hashed_pony
6 months ago
Forwarded emails DO NOT have headers on the original email. AF is correct. Source: I'm already an analyst and I've seen this multiple times.
upvoted 4 times
...
SH_
7 months ago
Selected Answer: AF
Answer is AF. Note that when an email is forwarded, the headers of the original email are not included. So I'll go with AF.
upvoted 3 times
...
Melmen
8 months, 2 weeks ago
Option BF - Checking the email header and check the SFP...
upvoted 1 times
...
zecomeia_007
9 months, 2 weeks ago
Selected Answer: BF
B. Review the headers from the forwarded email F. Examine the SPF, DKIM, and DMARC fields from the original email
upvoted 1 times
...
RiccardoBellitto
11 months, 3 weeks ago
Selected Answer: BF
Guys, as a SOC analyst we review the headers and I knowing how CompTIA say things unclearly, I think the "Forwarded" email referee the "Forwarding Email IOC" where, according to the CompTIA Study Guide provided by Dion Training: Forwarding â–Ş When a phishing email is formatted to appear as if it has come as part of a reply or forward chain So, I'm going with BF
upvoted 4 times
...
BanesTech
1 year ago
The answer is B,F. While the forwarded email may not include the complete set of original headers, it often includes headers indicating the path the email took from the sender to the recipient. These headers can still provide insights into the email's origin, intermediate servers it passed through, and other relevant information for assessing its legitimacy and security implications.
upvoted 2 times
...
section8santa
1 year ago
Selected Answer: EF
E. Evaluate the HELO or EHLO string of the connecting email server: The HELO or EHLO string is part of the SMTP (Simple Mail Transfer Protocol) session initiation and can provide information about the email server that initiated the connection. By examining this string, the analyst can determine if the server is a known or expected sender, which can be a critical factor in assessing the email’s legitimacy. F. Examine the SPF, DKIM, and DMARC fields from the original email: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) are email authentication methods that help prevent email spoofing. Analyzing these fields in the email header can help the analyst determine if the email genuinely originated from the stated domain or if it’s a spoofed email.
upvoted 1 times
...
CyberJackal
1 year ago
Selected Answer: BF
B&F imo.
upvoted 1 times
...
Kamel_
1 year, 2 months ago
As for someone who works in the SOC, we take a look at "BF" first.
upvoted 5 times
madx411
1 year, 1 month ago
you dont review forwarded email but email sent to you as attachment., so B is wrong.
upvoted 4 times
Wutan
1 year ago
Very nicely caught. The answer fooled me too. The header from the forwarded email would not contribute to the analysis.
upvoted 1 times
...
...
...
bmadajczyk
1 year, 4 months ago
Selected Answer: BF
If you are 'lucky' one of the first to be attacked by a phishing campaign, scoring will tell you nothing unfortunately.
upvoted 9 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago