Courseiva

CCNA Email Incidents Questions

30 questions · Email Incidents · All types, answers revealed

1
MCQeasy

What is the primary risk associated with 'Executive Spoofing' or BEC (Business Email Compromise)?

A.Financial loss via unauthorized transfers
B.System performance degradation
C.Infrastructure downtime
D.Spam distribution
AnswerA

This is the primary motive.

Why this answer

BEC targets employees to perform unauthorized financial transfers through social engineering.

2
MCQeasy

Which action should be taken after an email incident is contained and the indicators are identified?

A.Update security controls and user awareness programs
B.Ignore the event to focus on the next
C.Decommission the email server
D.Immediately delete all logs
AnswerA

This is the standard post-incident step.

Why this answer

Post-incident activities include updating policies and procedures to prevent recurrence.

3
MCQmedium

Which protocol is used in conjunction with SPF and DKIM to provide instructions to the receiver on how to handle emails that fail authentication?

A.SMTPS
B.IMAP
C.DMARC
D.POP3
AnswerC

DMARC defines the policy.

Why this answer

DMARC provides the policy instructions for SPF and DKIM failures.

4
MCQhard

When DKIM signature verification fails, what is the most likely technical cause?

A.The sender's IP address is on a blocklist
B.The body of the message was modified in transit
C.The user clicked a phishing link
D.The SPF record is missing
AnswerB

Modification breaks the cryptographic hash.

Why this answer

DKIM verification fails if the body content or headers were altered after signing.

5
MCQhard

While analyzing an email header, you observe an SPF 'softfail'. What does this imply?

A.The sending IP is not listed in the domain's SPF record
B.The message was spoofed and must be blocked
C.The email has been encrypted with TLS
D.The email passed DKIM verification
AnswerA

This is the definition of a softfail.

Why this answer

A softfail (~all) indicates the server is not explicitly authorized but the domain owner is not strictly enforcing rejection.

6
MCQhard

You are reviewing a suspicious macro in a Word document attachment. Which tool is best suited for static analysis of the macro code?

A.Oledump
B.Nmap
C.Wireshark
D.Volatility
AnswerA

Designed for macro analysis.

Why this answer

Oledump is the industry standard tool for identifying and extracting macros from Office documents.

7
Multi-Selectmedium

Which TWO of the following steps are required when performing a post-mortem analysis of an email incident?

Select 2 answers
A.Promoting the security analyst involved
B.Contacting the local law enforcement authorities
C.Evaluating the performance of security controls
D.Reviewing the incident response timeline and logs
E.Deleting all evidence to maintain privacy
AnswersC, D

Necessary to improve future detection.

Why this answer

Reviewing incident logs and evaluating the effectiveness of security controls are critical post-mortem steps.

8
Multi-Selecthard

Which THREE of the following email security technologies should be configured to prevent domain spoofing?

Select 3 answers
A.DKIM
B.SPF
C.SSL/TLS
D.HTTP/2
E.DMARC
AnswersA, B, E

Authenticates message integrity.

Why this answer

SPF, DKIM, and DMARC are the three pillars of email authentication to prevent spoofing.

9
MCQmedium

An organization uses Microsoft 365. Which feature should an admin use to globally remove a malicious phishing email from all user mailboxes?

A.Conditional Access policies
B.Exchange Transport Rules
C.Search and Purge in Microsoft 365 Defender
D.Mail Flow Connector configuration
AnswerC

This tool allows removing emails from mailboxes.

Why this answer

Search and Purge within the Microsoft 365 Defender portal is the standard tool for post-delivery removal.

10
MCQmedium

If a phishing email bypassed the perimeter email gateway, what is the next logical step in the incident response process?

A.Document the incident in the SIEM
B.Update the firewall blocklist
C.Attempt to contain the threat by removing the email
D.Wait for the user to report it again
AnswerC

Containment prevents further spread.

Why this answer

After detection, containment is the critical priority to prevent further impact.

11
MCQhard

An attacker uses a 'Homograph Attack' to spoof a domain. How does the analyst detect this?

A.Scanning the email for attachments
B.Checking the SPF record
C.Looking for a valid TLS certificate
D.Inspecting the Punycode representation of the domain
AnswerD

Punycode exposes the fake characters.

Why this answer

Homograph attacks use look-alike characters (like Cyrillic 'а' instead of Latin 'a') that are visible when inspecting the Punycode version of the domain.

12
Multi-Selectmedium

Which TWO of the following describe the role of an email gateway in incident response?

Select 2 answers
A.Replacing all passwords automatically
B.Filtering and blocking malicious content
C.Manually deleting user account files
D.Providing logs for forensic investigation
E.Encrypting all outgoing traffic
AnswersB, D

Proactive protection.

Why this answer

Email gateways act as a filter for incoming threats and provide logs for post-incident investigation.

13
MCQeasy

An employee receives a suspicious email asking to verify account details by clicking a link. What is the most effective user behavior to mitigate this?

A.Reply to the sender to verify
B.Use the organization's 'Report Phishing' tool
C.Ignore and delete the email without reporting
D.Forward it to a friend for a second opinion
AnswerB

This alerts the security team.

Why this answer

Reporting the suspicious email through the provided 'Report Phishing' button is the most effective user action.

14
Multi-Selectmedium

Which THREE of the following are common indicators of a phishing email?

Select 3 answers
A.Urgent or threatening language requiring immediate action
B.Mismatch between the display name and actual sender address
C.The email uses standard corporate branding
D.The URL visible in the text does not match the actual hyperlink
E.The email is sent during business hours
AnswersA, B, D

Urgency is used to bypass critical thinking.

Why this answer

Suspicious sender domains, mismatched URLs, and sense of urgency are primary phishing indicators.

15
MCQmedium

You are analyzing an email with a suspicious attachment. You notice the file name is 'invoice.pdf.exe'. What does this indicate?

A.The file is a double-extension obfuscation attempt
B.The file is a legitimate script file
C.The file is encrypted with a password
D.The file is a genuine PDF that requires an executable
AnswerA

Windows often hides the final extension.

Why this answer

The double extension is a common technique to trick users into executing a binary file.

16
MCQeasy

When performing manual phishing triage, which action should an analyst perform first after identifying a suspicious URL in an email body?

A.Click the URL to inspect the landing page
B.Block the sender domain immediately
C.Run the URL against an automated sandbox analysis tool
D.Forward the email to the user for confirmation
AnswerC

Safe detonation is the primary first step.

Why this answer

Before interaction, you must detonate in a sandbox to ensure safety.

17
MCQeasy

An analyst is drafting an email to a user who reported a phishing attempt. What is the most important tone to maintain?

A.Professional, calm, and informative
B.Accusatory, to discourage clicking
C.Technical and jargon-heavy
D.Alarmist, to ensure they remain scared
AnswerA

This promotes trust and cooperation.

Why this answer

The tone should be professional, reassuring, and helpful to encourage future reporting.

18
MCQmedium

Which of the following is a symptom of an 'Email Forwarding Rule' attack?

A.The user's inbox is empty
B.Emails are being forwarded to an external address
C.The mailbox reached its size limit
D.The password was changed
AnswerB

This is the hallmark of the attack.

Why this answer

Attackers set up auto-forwarding rules to intercept sensitive business communications without the user's knowledge.

19
MCQhard

An analyst identifies that an email originated from an unauthorized IP address despite passing SPF. What is the most likely cause?

A.The user's computer is infected
B.The SPF record is too broad
C.The domain has no DMARC record
D.The mail server was misconfigured
AnswerB

Broad SPF records allow unauthorized senders.

Why this answer

If SPF passes but the IP is wrong, it is likely the attacker is using an email service that is part of the same SPF-authorized infrastructure (like a shared cloud provider).

20
Multi-Selecthard

Which THREE of the following could be considered 'indicators of compromise' (IOCs) for an email incident?

Select 3 answers
A.Malicious URL within the email body
B.The name of the email service provider
C.Sender IP address
D.MD5 or SHA-256 hash of an attachment
E.The user's password
AnswersA, C, D

Common phishing IOC.

Why this answer

Sender IP addresses, malicious URLs, and file hashes are standard IOCs.

21
Multi-Selecteasy

Which THREE of the following are appropriate communication channels to keep users informed during an email phishing incident?

Select 3 answers
A.Individual user personal phone numbers
B.Corporate security intranet portal
C.Public social media accounts
D.Official company-wide security alert email
E.Internal helpdesk ticketing system status page
AnswersB, D, E

Appropriate for awareness.

Why this answer

Company-wide announcements, helpdesk tickets, and security awareness portals are appropriate channels.

22
MCQhard

An email header contains 'X-Forefront-Antispam-Report'. What can an analyst determine from this?

A.The email is definitely malicious
B.The sender is a known spammer
C.The email is encrypted
D.The email was scanned by Microsoft's filtering engine
AnswerD

This header is specific to Microsoft services.

Why this answer

This header provides information on how Microsoft's filtering engine analyzed the message, including spam confidence levels.

23
MCQeasy

When an email incident is resolved, why is it necessary to update the organization's blocklist?

A.To comply with legal regulations
B.To prevent re-occurrence of the same campaign
C.To improve system performance
D.To delete the user's account
AnswerB

This is the core purpose of blocklisting.

Why this answer

Updating the blocklist prevents future delivery of emails from the same source or with the same malicious artifacts.

24
Multi-Selecteasy

Which TWO of the following are safe practices when analyzing a suspicious email?

Select 2 answers
A.Disabling all antivirus tools to observe behavior
B.Opening attachments in your primary email client
C.Ensuring the analysis environment is isolated from the network
D.Clicking every link to check for live sites
E.Performing analysis in an isolated virtual machine
AnswersC, E

Prevents data exfiltration.

Why this answer

Using virtual machines and disconnecting from the corporate network are safe practices.

25
MCQmedium

You are analyzing an email and the URL redirects through multiple shortened link services. What is the recommended way to find the final landing page?

A.Click the link to see where it goes
B.Block all shortened links
C.Run a packet capture on the gateway
D.Use a URL lookup or unshortening service
AnswerD

This is the safe way to resolve redirects.

Why this answer

Using a 'URL unshortening' service or tool allows the analyst to see the final destination without clicking the link.

26
MCQmedium

What is the purpose of 'Sandboxing' in email security?

A.To provide a backup of the email
B.To store malicious emails for future reference
C.To encrypt the email body
D.To safely execute and observe file behavior
AnswerD

This is the core function.

Why this answer

Sandboxing executes a file in a controlled, virtual environment to observe its behavior before allowing it to reach the end user.

27
MCQeasy

An analyst receives a report of a phishing email. Which email header field is most reliable for verifying the path taken by the email through intermediate mail transfer agents?

A.X-Originating-IP
B.Return-Path
C.X-Mailer
D.Received
AnswerD

This header tracks the path through servers.

Why this answer

The Received header is added by every MTA that handles the message, providing a verifiable path.

28
Multi-Selectmedium

Which THREE of the following items should be included in an email incident report?

Select 3 answers
A.Chronological timeline of the incident
B.Personal contact information of the attacker
C.List of affected users or systems
D.Full history of every email ever sent to the user
E.Remediation steps taken
AnswersA, C, E

Essential for reconstruction.

Why this answer

A description of the incident, the impact, and the remediation steps are required for a report.

29
MCQmedium

If a user receives an email with an attachment that is a 'compressed password-protected file', why is this a red flag?

A.It requires too much storage space
B.It is a sign of high security
C.It prevents security gateways from scanning the contents
D.It violates corporate policy
AnswerC

This is the primary evasion goal.

Why this answer

Password protection hides the file contents from automated antivirus scanners.

30
Multi-Selecthard

Which TWO of the following are valid methods to identify a malicious attachment?

Select 2 answers
A.Forwarding the email to the entire company
B.Performing behavioral analysis in a sandbox
C.Checking the file hash against a known threat database
D.Opening the attachment on a personal device
E.Deleting the attachment based on its size
AnswersB, C

Effective for unknown malware.

Why this answer

Analyzing file hashes against threat intelligence and performing behavioral analysis in a sandbox are valid methods.

Ready to test yourself?

Try a timed practice session using only Email Incidents questions.