Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 94 Topic 10 Discussion

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 94 Topic 10 Discussion

CS0-003 Exam Topic 10 Question 94 Discussion:
Question #: 94
Topic #: 10

A security analyst reviews a SIEM alert related to a suspicious email and wants to verify the authenticity of the message:

SPF = PASS

DKIM = FAIL

DMARC = FAIL

Which of the following did the analyst most likely discover?


A.

An insider threat altered email security records to mask suspicious DNS resolution traffic.


B.

The message was sent from an authorized mail server but was not signed.


C.

Log normalization corrupted the data as it was brought into the central repository.


D.

The email security software did not process all of the records correctly.


Get Premium CS0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.