I7 Module Test: Email Security and Phishing Defense
Demonstrate that you can analyze fictional messages, sender identities, authentication, social engineering, links, attachments, business email compromise, filtering decisions, logs, user actions, account evidence, business impact, and case closure.
Lesson Progress
Module Test
High School Intermediate • I7: Email Security and Phishing Defense • Lesson 9 of 9
Readiness Check
Module Test Readiness
0/8 ready
Test Instructions
Complete the Assessment Like a Defender
Answer all twenty-five questions before revealing explanations.
Use the strongest evidence-based answer, not the most dramatic answer.
Treat every message, domain, address, link, attachment, user, account, device, vendor, and organization as fictional.
Separate authentication, legitimacy, interaction, account impact, and business impact.
Choose independent verification paths that do not rely on suspicious message content.
Do not assume a security-tool verdict, warning, delivery state, click, or failed sign-in proves the entire case.
Use narrow containment and validation instead of broad blocking or unsupported account actions.
Review missed questions by identifying the exact evidence layer you confused.
Review Map
Eight Areas Covered by the Test
Area 1
Message anatomy and threat landscape
Separate the fictional visible message, sender claim, transport path, filtering decision, delivery state, mailbox activity, user interaction, account activity, and business impact.
Area 2
Sender identity and authentication
Interpret fictional display names, actual addresses, domains, Reply-To, envelope senders, SPF, DKIM, DMARC, and alignment without treating authentication as complete legitimacy.
Area 3
Social engineering
Recognize fictional urgency, authority, fear, curiosity, secrecy, scarcity, helpfulness, familiarity, impersonation, pretext, and business-process bypass.
Area 4
Links and attachments
Distinguish fictional visible link text, encoded and final destinations, redirects, QR codes, cloud shares, file names, content types, structures, security verdicts, and interaction stages.
Area 5
Business email compromise
Evaluate fictional executive impersonation, vendor fraud, payroll diversion, gift-card requests, invoice changes, compromised accounts, and reply-chain abuse.
Area 6
Email security controls
Explain fictional allow, warn, junk, quarantine, reject, block, post-delivery action, false positives, false negatives, narrow tuning, exceptions, validation, and rollback.
Area 7
Logs and investigation
Correlate fictional message traces, headers, gateway events, mailbox events, URL records, attachment events, identity activity, user reports, business systems, and evidence gaps.
Area 8
Integrated defense
Create separate conclusions for the fictional message, each recipient, account or device activity, business impact, control performance, response, monitoring, and closure.
Check Your Understanding
I7 Module Test: 25 Questions
Choose your answers first. Explanations appear only after submission.
1. Which statement best describes the visible inbox view of a fictional message?
2. A fictional display name matches the organization’s Finance Director, but the actual address uses an unfamiliar external domain. What is the strongest response?
3. What does a fictional SPF pass most directly support?
4. What does a fictional DKIM pass most directly support?
5. A fictional lookalike domain passes SPF, DKIM, and DMARC for itself. Which conclusion is strongest?
6. Which fictional message most clearly uses secrecy as a social-engineering technique?
7. Why is professional grammar weak evidence of message legitimacy?
8. Which combination most strongly supports a fictional phishing pattern?
9. What is the safest way to verify an unexpected fictional password-expiration message?
10. Why should visible link text not be trusted by itself?
11. A fictional link uses HTTPS and displays a familiar login page. What does HTTPS prove?
12. A fictional attachment named Invoice.pdf is detected as HTML content. What is the strongest response?
13. Which statement correctly separates fictional attachment stages?
14. A fictional known vendor domain sends an urgent bank-account change and passes aligned authentication. What is the safest action?
15. Which evidence combination most strongly supports possible compromise of a fictional legitimate vendor mailbox?
16. Why is a narrow transaction hold useful during a fictional BEC investigation?
17. What does a fictional gateway quarantine decision directly represent?
18. What is the strongest response to a fictional false positive affecting a required vendor invoice?
19. Which fictional allowlist design is strongest?
20. What is post-delivery quarantine?
21. Which source most directly confirms fictional message delivery and final mailbox or quarantine state?
22. A fictional URL-protection record confirms a click. What is the strongest direct conclusion?
23. Why should fictional timestamps be normalized during an investigation?
24. A fictional user clicks a phishing page, but no form submission, factor change, recovery, persistent session, or application change is found. Which conclusion is strongest?
25. Which module-closure plan is strongest?
Score Interpretation
Use Your Result to Guide Review
23–25 correct
Strong module mastery. Review explanations for any missed evidence limitations.
20–22 correct
Ready to continue after reviewing the specific topics connected to missed questions.
16–19 correct
Revisit the lessons on authentication, interaction stages, business verification, and investigation evidence.
0–15 correct
Review I7.1 through I7.8 and repeat the test after rebuilding your evidence-based reasoning.
Defender Habits
I7 Module Mastery Checklist
Portfolio Prompt
Module Completion Artifact
Revise your fictional I7.8 Meadowbrook Email Security and Phishing Defense Case Report using what you learned from the module test. Add a one-page correction log that identifies each missed question, the evidence layer you confused, the corrected reasoning, and the lesson section you reviewed.
Key Takeaways
What You Should Remember
Navigation