Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA Exam CS0-003 Topic 2 Question 41 Discussion

Actual exam question for CompTIA's CS0-003 exam
Question #: 41
Topic #: 2
[All CS0-003 Questions]

A security analyst reviews a SIEM alert related to a suspicious email and wants to verify the authenticity of the message:

SPF = PASS

DKIM = FAIL

DMARC = FAIL

Which of the following did the analyst most likely discover?

Show Suggested Answer Hide Answer
Suggested Answer: B

Comprehensive and Detailed Step-by-Step The SPF = PASS result confirms the email came from an authorized server, but DKIM = FAIL indicates the message was not properly signed with the expected DomainKeys Identified Mail (DKIM) signature. DMARC = FAIL suggests that because DKIM failed, the overall email authentication failed. This scenario is consistent with a legitimate server sending an unsigned email.


CompTIA CySA+ All-in-One Guide (Chapter 5: Email Analysis)

CompTIA CySA+ Practice Tests (Domain 1.3 Email Authentication)

Contribute your Thoughts:

Devora
3 days ago
I agree with Lavina, DKIM and DMARC failing indicates lack of proper email signing.
upvoted 0 times
...
Lavina
4 days ago
I think the analyst discovered that the message was sent from an authorized mail server but was not signed.
upvoted 0 times
...

Save Cancel