โ† All CHFI Flashcard Decks

Email and Social Media Forensics Flashcards

6 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Email and Social Media Forensics flashcards as text
  1. Which email header field is most important for tracing the originating IP address of an email message?

    Answer: Received

    The 'Received' headers form a chain of mail server hops and the earliest 'Received' header contains the originating IP address of the sender.

  2. In email forensics, what does the 'X-Originating-IP' header reveal?

    Answer: The IP address of the client that originally submitted the email

    The X-Originating-IP header, added by some mail providers, records the IP address of the device that originally sent the email, which can identify the sender's location.

  3. Which tool is commonly used by CHFI investigators to analyze email headers and trace email origins?

    Answer: MXToolbox Email Header Analyzer

    MXToolbox Email Header Analyzer parses raw email headers to display the routing path, timestamps, and originating IP addresses in an investigator-friendly format.

  4. What is the forensic significance of the MIME (Multipurpose Internet Mail Extensions) structure in email investigation?

    Answer: It encodes attachments and multi-part content that may contain embedded malware or evidence

    MIME encoding allows emails to carry attachments and multi-part content; forensic investigators must decode MIME parts to extract and examine potentially malicious or evidential attachments.

  5. Which email authentication mechanism adds a digital signature to outgoing emails that can be verified to confirm the sender's domain integrity?

    Answer: DKIM

    DKIM (DomainKeys Identified Mail) adds a cryptographic signature to the email header that allows receivers to verify the email was not altered and originated from the claimed domain.

  6. During an email forensics investigation, what does a missing or broken DMARC alignment indicate?

    Answer: The email may be a phishing attempt or spoofed to impersonate a legitimate domain

    Failed DMARC alignment indicates that SPF and/or DKIM checks failed, suggesting the email may be spoofed or sent by an unauthorized server impersonating the domain.