CHFI Application, Email and Cloud Forensics Practice Question
A security analyst is investigating a phishing email and notices the DKIM-Signature header is present but fails validation. Which TWO actions should the analyst take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the DKIM DNS record for the signing domain
DKIM failure indicates the email may be forged or tampered with. Checking the domain's DKIM DNS record and examining the email headers for other spoofing indicators are appropriate steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore the DKIM failure as it is not important
Why it's wrong here
DKIM failure is a critical authentication red flag that warrants immediate investigation, not dismissal. A signature failure means the message either was altered in transit, lacked a proper key synchronization, or the sender's domain is being spoofed, and ignoring it could allow a phishing email to bypass defenses. The analyst should retrieve the full DKIM header and compare it against the published DNS key.
- ✓
Check the DKIM DNS record for the signing domain
Why this is correct
The correct forensic step is to query the DNS TXT record for the selector and signing domain using tools like dig or nslookup, then use that public key to cryptographically verify the DKIM signature in the email headers. If the key is missing, expired, or does not match, this confirms the failure is due to a real spoofing attempt or misconfiguration. This validation is objective and reproducible, unlike replying or deleting evidence.
- ✗
Reply to the sender to verify authenticity
Why it's wrong here
Replying to the sender to verify authenticity is a counterproductive and dangerous action during a phishing investigation. Email addresses can be easily spoofed, so a reply may go directly to the attacker, revealing that the recipient address is active and inviting further targeted attacks, while providing no forensic evidence. A proper investigation relies on analyzing headers and authentication records, not interacting with a potentially hostile entity.
- ✓
Examine the Received headers for spoofing clues
Why this is correct
Examining the Received headers is an essential investigation step because each mail server that handles the message appends a Received line containing IP addresses, hostnames, and timestamps, which together trace the email's path from origin to destination. Anomalies such as inconsistent hostnames, mismatched IP ranges, or a sender forging the 'from' domain without corresponding hops can expose spoofing. This header analysis is a passive, evidence-preserving technique that complements cryptographic checks like DKIM.
- ✗
Delete the email immediately
Why it's wrong here
Deleting the email immediately destroys the primary evidence required for forensic analysis, potentially violating organizational retention policies and hindering any legal or disciplinary proceedings. Without the raw message, including full headers, MIME structure, and metadata, investigators lose the ability to perform header analysis, extract indicators of compromise, or validate authentication records. The correct action is to preserve the email as an immutable artifact, typically by exporting the .eml file or making a forensically sound copy.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.