CertaDNS

Email Security Practitioner — assessment

questions
15
to pass
80%
retakes
Unlimited
time limit
None

Covers

  • Auditing a Domain Cold
  • Designing the Programme
  • Three Incidents
  • Explaining It
  • What None of It Stops
  • End to End

Sample question

Domain A publishes p=reject, a 1024-bit DKIM key and no MTA-STS. Domain B publishes p=none with rua, 2048-bit keys and an enforcing MTA-STS policy. Which has the more serious finding?

  • Domain B — p=none means anyone can send as it today, and the other findings do not offset that.Rank by what a finding permits, not by how technical it sounds. B has excellent hygiene around a policy that asks receivers to take no action; A’s weaknesses each require an attacker to achieve something difficult first.
  • Domain A — a 1024-bit key is a cryptographic weakness.Factoring a 1024-bit key is a laboratory undertaking. Sending mail as a domain at p=none requires an SMTP client.
  • Domain A — missing MTA-STS leaves inbound mail interceptable.It requires an attacker already positioned on the network path. Spoofing B requires nothing at all.
  • Equally serious, since each has findings in several categories.Counting findings is what automated scores do, and it is why a well-configured domain at p=none can score better than a protected one.

Every option carries an explanation, including the wrong ones.

The assessment needs an account.

Passing issues Email Security Practitioner. A CertaDNS Academy certificate records that you completed a course and passed its assessment on a given date. It is not a professional certification, it is not accredited, and it does not expire.