exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 144 discussion

Actual exam question from CompTIA's CS0-002
Question #: 144
Topic #: 1
[All CS0-002 Questions]

A company's domain has been spoofed in numerous phishing campaigns. An analyst needs to determine why the company is a victim of domain spoofing, despite having a DMARC record that should tell mailbox providers to ignore any email that fails DMARC. Upon review of the record, the analyst finds the following: v=DMARC1; p=none; fo=0; rua=mailto:[email protected]; ruf=mailto:[email protected]; adkim=r; rf=afrf; ri=86400;
Which of the following BEST explains the reason why the company's requirements are not being processed correctly by mailbox providers?

  • A. The DMARC record's DKIM alignment tag is incorrectly configured.
  • B. The DMARC record's policy tag is incorrectly configured.
  • C. The DMARC record does not have an SPF alignment tag.
  • D. The DMARC record's version tag is set to DMARC1 instead of the current version, which is DMARC3.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DaroKa
Highly Voted 2 years, 7 months ago
Selected Answer: B
I agree with B p=none - Take no action on the message and deliver it to the intended recipient. should be p=reject or p=qarantine
upvoted 10 times
sh4dali
2 years, 7 months ago
Correct
upvoted 1 times
...
PTcruiser
2 years, 7 months ago
https://mxtoolbox.com/dmarc/details/how-to-setup-dmarc For the "p" tag pair "p=" can be paired with none, quarantine, or reject. As tag-value pairs they would look like:p=none or p=quarantine or p=reject MxToolbox recommends all new DMARC records should start with p=none, as this policy value allows you to identify email delivery problems due to the domain's SPF or DKIM so that mail isn't accidentally quarantined or rejected
upvoted 3 times
Adrian831
2 years, 7 months ago
After a closer look I think you are right, so the correct answer here should be C
upvoted 3 times
...
...
...
AC6280
Highly Voted 2 years, 2 months ago
Selected Answer: B
To add more clarity here (I worked specifically in email security). It is not required to have an SPF alignment tag (ASPF tag). https://easydmarc.com/blog/what-are-dmarc-tags-dmarc-tags-explained/ Even if you did have it, DMARC policy is in monitor only mode (p=none), so it wouldn't matter. The policy is never going to be enforced until you move it to p=quarantine at the minimum (very few orgs actually hit a p=reject stage, it's incredibly difficult).
upvoted 8 times
2Fish
2 years, 1 month ago
Agree. Thank you for the explanation.
upvoted 1 times
...
...
MacheenZero
Most Recent 1 year, 8 months ago
Selected Answer: C
This is an example of a DMARC policy record. The v and p tags must be listed first, other tags can be in any order: Example: v=DMARC1; p=reject; rua=mailto:[email protected], mailto:[email protected]; pct=100; adkim=s; aspf=s You can choose from two alignment modes: strict and relaxed. Set the alignment mode for SPF and DKIM in the DMARC record. The aspf and adkim DMARC record tags set the alignment mode. In the following cases, we recommend you consider changing to strict alignment for increased protection against spoofing: Mail is sent for your domain from a subdomain outside your control You have subdomains that are managed by another entity To pass DMARC, a message must pass at least one of these checks: SPF authentication and SPF alignment DKIM authentication and DKIM alignment A message fails the DMARC check if the message fails both: SPF (or SPF alignment) DKIM (or DKIM alignment) Important: Relaxed alignment typically provides sufficient spoofing protection. Strict alignment can result in messages from associated subdomains to be rejected or sent to spam. https://support.google.com/a/answer/10032169?hl=en
upvoted 1 times
...
[Removed]
2 years ago
Selected Answer: B
I would go with B as well.. Here is what I found about setting up Policies and email spoofing. Take a look at the Final Notes towards the bottom. https://4sysops.com/archives/set-up-dmarc-for-spf-and-dkim/
upvoted 1 times
...
Cyber_Guru
2 years, 2 months ago
Selected Answer: A
“adkim=” This sets the DKIM portion of DMARC authentication to either “s” for strict or “r” for relaxed. The strict setting ensures DKIM will only pass if the “d=” field in the signature precisely matches the “from” domain. When set to relaxed, messages will pass DKIM only if the “d=” field matches the root domain of the “from” address.
upvoted 1 times
...
IanRogerStewart
2 years, 3 months ago
Selected Answer: C
Actually must be C. It must have an aspf tag which is missing
upvoted 1 times
...
IanRogerStewart
2 years, 3 months ago
Selected Answer: A
The alignment tag is set to 'R' meaning relaxed. Any valid subdomain of d=domain in the DKIM mail headers is accepted. Should be set to 'S' strict.
upvoted 2 times
...
TIM0088
2 years, 4 months ago
Selected Answer: B
the policy tag is set to "none," which means that mailbox providers should not take any action on email that fails DMARC. This is likely the reason why the company's domain is being spoofed in numerous phishing campaigns, as mailbox providers are not blocking or quarantining the suspicious emails. To fix this issue, the analyst should change the value of the policy tag to "quarantine" or "reject" to instruct mailbox providers to take appropriate action on email that fails DMARC. B is the correct ans
upvoted 2 times
...
forklord72
2 years, 6 months ago
Selected Answer: C
I did research on DMARC and to pass DMARC, you must pass SPF authentication and alignment. I see nothing about SPF alignment in the code so I think it should be C.
upvoted 1 times
forklord72
2 years, 6 months ago
I was wrong here, answer is B. The emails were not failing DMARC which is the problem making the answer B.
upvoted 2 times
...
...
ryanzou
2 years, 7 months ago
Selected Answer: B
B p=none
upvoted 1 times
...
TheSkyMan
2 years, 7 months ago
Selected Answer: C
I'm feeling C. "The way it works is to help email receivers determine if the purported message “aligns” with what the receiver knows about the sender." https://dmarc.org/overview/
upvoted 2 times
...
piotr3439
2 years, 7 months ago
Selected Answer: B
I agree B
upvoted 2 times
...
Laudy
2 years, 8 months ago
Literally no idea... Hope B is right....
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago