CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 433


An organization suspects it is receiving spoofed e-mails from a foreign-hosted web e-mail service. Where can the MOST relevant be found to begin the process of identifying the perpetrator?

Show Answer
Correct Answer: B

The most relevant information to begin the process of identifying the perpetrator of spoofed e-mails can be found in the message headers of the received e-mails. The headers contain crucial details such as the originating IP address, the path taken by the email, and other metadata that can be used to trace the source of the email and determine if it has been spoofed.

Discussion

3 comments
Sign in to comment
Arsh_2022Option: B
Mar 1, 2023

Answer B is right: The most relevant place to begin the process of identifying the perpetrator would be to analyze the email headers. Email headers contain detailed information about the sender, including the IP address of the originating server. This information can be used to trace the source of the email and determine whether it is indeed being spoofed.

jackdryan
May 16, 2023

B is correct

evilCorpBot7494Option: B
Mar 2, 2024

The question specifies "to begin the process". That makes B) the best answer. If it didn't specify that, A) would be the right answer.

73f8ac3Option: B
May 24, 2024

Emails header can sometimes have a lot of information in them, quite easily accessible. That's also why when forwarding a suspicious email to the relevant security service, the email must not be just forwarded, but rather joined as attachement, so as to preserve the headers in it.