GSEC Security Frameworks and CIS Controls Practice Question
An organization is applying CIS Control 9: Email and Web Browser Protections. They have successfully implemented domain-based message authentication (DMARC). What is the primary security goal being achieved by this implementation?
⚠ Common exam trap
Candidates often confuse DMARC with encryption protocols like TLS or general spam filtering, missing its specific focus on domain spoofing prevention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prevention of unauthorized use of the organization's domain for spoofing.
DMARC is a critical component of CIS Control 9 because it builds upon SPF and DKIM to prevent email spoofing and phishing attacks. By allowing domain owners to publish instructions on how receiving servers should handle emails that fail authentication, it significantly reduces the efficacy of fraudulent emails, thereby protecting the organization's reputation and preventing users from interacting with malicious content that leverages the organization's legitimate email domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encryption of email traffic between mail servers.
Why it's wrong here
DMARC does not provide encryption for email traffic. Encryption for transit is typically handled by protocols like TLS (Transport Layer Security). DMARC is an authentication mechanism designed to verify the sender's identity and detect spoofing, not to ensure confidentiality or privacy of the email content while it is moving.
- ✓
Prevention of unauthorized use of the organization's domain for spoofing.
Why this is correct
DMARC specifically enables domain owners to protect their domain from being used for email spoofing. It provides a feedback mechanism and policy enforcement that tells receiving mail servers how to reject or quarantine emails that do not pass SPF or DKIM authentication, directly preventing domain impersonation and phishing.
- ✗
Hardening web browser settings to prevent XSS attacks.
Why it's wrong here
Web browser protections in CIS Control 9 focus on security settings like disabling insecure plug-ins and using secure configuration templates to prevent attacks such as XSS. DMARC is strictly an email authentication protocol and provides no direct protection for web browser behavior or web-based application vulnerabilities.
- ✗
Scanning of inbound email attachments for malware signatures.
Why it's wrong here
Scanning email attachments for malware is a function of an email security gateway or antivirus solution. DMARC does not inspect the content of emails or attachments. It solely validates the identity of the sender to ensure the email genuinely originated from the claimed domain owner.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.