Email Monitoring Flashcards

1
Q

Spear Phishing

A

An email spoofing attack targeting a specific organization or individual by
seeking unauthorized access to sensitive information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

BEC

A

An impersonation attack in which the attacker gains control of an
employee’s account and uses it to convince other employees to perform
fraudulent actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Forwarding

A

When a phishing email is formatted to appear as if it has come as part of
a reply or forward chain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Email Internet Header

A

A record of the email servers involved in transferring an email message
from a sender to a recipient
Exploit 3 address fields in email
Display From Support@diontraining.com theft@badguy.com
Envelope From Various labels hidden from mail client
Received From/By List of the MTAs that processed email

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Email Server Security

A

Spoofing attacks can be mitigated by configuring authentication for email server
systems. SPF, DKIM, and DMARC do not solve the problem of cousin domains

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SPF

A

DNS record identifying hosts authorized to send mail for the domain with
only one being allowed per domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

DKIM

A

Provides a cryptographic authentication mechanism for mail utilizing a
public key published as a DNS record

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

DMARC

A

A framework for ensuring proper application of SPF and DKIM utilizing a
policy published as a DNS record

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

SMTP Log analysis codes

A

Code 220 indicates the server is ready
Code 250 indicates the message is accepted
Code 421 indicates the service is not available
Code 450 indicates that the server cannot access the mailbox to deliver a
message
Code 451 indicates the local server aborted the action due to a
processing error
Code 452 indicates the local server has insufficient storage space
available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

S/MIME

A

An email encryption standard that adds digital signatures and public key
cryptography to traditional MIME communications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Email Content Analysis

A

An attacker must also craft some sort of payload to complete the exploit when a
victim opens a message

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

MIME

A

Allows a body of an email to support different formats, such as HTML,
rich text format (RTF), binary data encoded as Base64 ASCII characters,
and attachments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly