Email Fraud Defense Flashcards

1
Q

Email Fraud Defense

A

makes our email authentication simpler and can help us identify which email senders are legitimate and monitor anomalous senders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

DNS

A

Domain Name System; naming system for computers, services, and other resources in the Internet or other Internet Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SPF

A

Sender Policy Framework (SPF) including its implementation, and challenges; checks if server is authorized to send email on behalf of the domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

DKIM

A

DomainKeys Identified Mail (DKIM) including its implementation and challenges; Digital signature.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Outbound email gateway

A

outgoing mail server or SMTP server that sends email from a domain to external recipients on the internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Domain

A

main part of website URL that reps company or entity on internet; contains TLD and SLD (ex: dell.com)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Subdomain

A

subset of a larger and is used to organize and structure content within the main domain (ex: erg.dell.com)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SPF alignment

A

when the message’s SPF domain and the header’s From: domain match, or share the same parent domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

DKIM alignment

A

the DKIM domain found in the DKIM signature matches the header’s From: domain or DKIM signature matches the Header’s From: domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Relaxed

A

subdomains are aligned with parent domains

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Strict

A

domains MUST match exactly (ex: us.erg.dell.com would NOT align with erg.dell.com)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How do you pass DKIM?

A

a message must pass EITHER SPF and SPF alignment or DKIM signatures, only one needs to pass and align DKIM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Policy=none

A

tells recipient networks to ignore that the email fails DMARC authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Policy=quarantine

A

tells recipient networks to quarantine messages that fail DMARC authentication; ends up in spam or junk folder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Aggregate reports provide high level info on…

A

o IP address of sender
o Total number of emails sent by a sender
o SPF, DKIM, and DMATC authentication results of those emails; includes all metadata

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Policy=reject

A

tells recipient networks to block any mails that fail DMARC authentication

17
Q

Splunk

A

big data platform that simplifies the task of collecting and managing massive amounts of data

18
Q

Email authentication in Proofpoint

A

similar to how airports manage security; in Proofpoint, their multilayered defense uses identity control and content analysis to protect organizations from email fraud (like a passport)

19
Q

Domain Message Authentication, Reporting and Conformance (DMARC) authentication

A

allows senders to indicate if messages are PROTECTED by two popular authentication techniques and tells receivers what to do if neither pass

20
Q

Proofpoint

A

gives us visibility into most of the emails that are coming in and out of our org; can authorize legit senders trying to send email on your behalf or block them from spoofing your domains or your suppliers