QuestionQ27

Security Operations

A security analyst needs to ensure email domains that send phishing attempts without previous communications are not delivered to mailboxes. The following email headers are being reviewed:

Question Image

Which of the following is the best action for the security analyst to take?

Explanation

The sales.com message is the only entry where the sending domain (sales.com) does not match the reply-to domain (sales-mail.com), a classic header-spoofing indicator used in phishing to redirect replies to an attacker-controlled mailbox, and it is a first-time sender with no prior correspondence. Vendor.com, partner.com, and hr-saas.com all show matching sending and reply-to domains; vendor.com in particular has an established, consistent domain across two messages, so it does not fit "without previous communications," making the sales-mail.com header mismatch the pattern that should be quarantined.

Community Discussion

No comments yet. Be the first to start the discussion!