Module 2 - E-mail Flashcards

1
Q

E-mail threats (3)

A
  • inbound email allowed by design
  • can be spoofed (if not digitally signed)
  • two paths (corporate system, personal/web-based)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Spam Characteristics

A
  • unsolicited commercial e-mail
  • no valid reply address
  • no affiliation with recipient
  • no ability to opt-out
  • sale of goods or services
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Phishing Attack

A

email tailored to an org or group of individuals

- malicious payload (exe, office with macros, PDFs with Javascript, hyperlinks)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Spear Phishing Attack

A
  • Target individuals (executives, senior mgmt, executive assistants, IT Staff)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Whaling attacks

A

form of spear phishing

Targets executives, senior mgmt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Email artifacts for threats

A
  • within e-mail
  • browser or app that establishes outbound connection
  • firewall/server logs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Email Analysis (within)

A

email header (proof of delivery, sender and return-path, servers/IP addresses)
body
attachments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Email Header correlations

A

Return-Path and From
X-Mailer with user and IP
Delivered-To and To (could be OK if BCC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Email locations (5)

A
Mail server
Journaling (if SOX compliant)
Local containers within profiles
temporary internet files
temp directories contain attachments
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Public IP and Emails

A

Yahoo appends public IP of sender to e-mails

Google does not.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Outlook Personal Folders (location)

A

C:\users\%username%\Local\Application Data\Microsoft\Outlook\

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Thunderbird Mail (location)

A

%USERPROFILE%\Application Data\Thunderbird\Profiles\XXXXXXXX.default\Mail\

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Windows.edb

A

C:\ProgramData\Microsoft\Search\Data\Application\Windows

-Windows indexer for searching

How well did you know this?
1
Not at all
2
3
4
5
Perfectly