Domain Abuse & Impersonation — assessment
- questions
- 15
- to pass
- 80%
- retakes
- Unlimited
- time limit
- None
Covers
- The Economics
- The Permutation Space
- Registration Signals
- Infrastructure Signals
- Certificates as a Channel
- Classifying a Finding
- What Detection Misses
Sample question
Two lookalike domains are found. One serves a cloned login page. The other has no content at all but publishes an MX record. Which deserves escalation?
- Both — and the MX one is the more dangerous, because mail receipt enables invoice redirection, the attack with the largest per-incident loss.The clone is active and harvests credentials at volume. The MX domain has been prepared for a targeted conversation with a named finance team, and one successful payment diversion exceeds an entire credential campaign.
- The cloned page, because it is live and the other is not.Being live makes it immediate rather than larger. A domain configured to receive mail is at a preparation stage, not an absence of intent.
- Neither, until the second one serves content.Waiting for content forfeits the only warning you were given.
- The MX one only, since a cloned page deceives few people.A clone served over HTTPS deceives plenty, and it is already operating.
Every option carries an explanation, including the wrong ones.
The assessment needs an account.
Passing issues Domain Impersonation Analyst. A CertaDNS Academy certificate records that you completed a course and passed its assessment on a given date. It is not a professional certification, it is not accredited, and it does not expire.