Work from the headers outward, in a safe environment. Check the sending path, SPF, DKIM and DMARC results, envelope versus display sender, and any reply to mismatch. Detonate links and attachments in a sandbox, never on your workstation. Extract indicators, then search mail logs for everyone else who received it and whether anyone clicked or authenticated. Contain by purging the message and blocking the infrastructure.
Why interviewers ask this
The interviewer is checking safe handling habits, header literacy, and whether you think past the single reported email to organizational scope. Many candidates analyze the sample and stop there. The strong answer pivots quickly to the question that actually matters: who else received it and who interacted with it. They also want the response actions you can take yourself versus what needs mail administrator support.
How to structure your answer
- State your handling precautions before you touch the sample.
- Read authentication results and the sender path first.
- Detonate and extract indicators in an isolated environment.
- Pivot immediately to organizational scope and containment.
Example answer
I never open it on my own box. I pull the original message with full headers from the mail platform, and I detonate anything live in a sandbox virtual machine with network capture running. Headers first: SPF, DKIM and DMARC results, the received chain, whether the envelope sender matches the display name, and whether the reply to address is a lookalike domain. Most credential phishing I have seen passes SPF because it is sent from a compromised legitimate tenant, so a pass on its own proves nothing. Then links: expand shorteners, follow redirect chains, and check whether the landing page is a harvester mimicking our own login page. Then I flip to scope, which matters more than the sample: search mail logs for the sender, subject and URL to find everyone who received it, check proxy logs for clicks, and check sign in logs for authentications from that infrastructure. Purge from all mailboxes, block the domain, reset anyone who authenticated.
Walking into this interview soon? GhostPilot listens to your live call, spots the question the moment it is asked, and puts a structured answer on your screen in real time. Try it on your next mock, or grab a $29 Session Pass, no subscription, for the real thing.
See how it worksFollow-up questions to expect
- What do you do if three users already entered credentials?
- How do you tell a credential harvester from a malware delivery page?
- How do you handle a phishing report that turns out to be a real vendor email?
Related cybersecurity analyst questions
Your interviewer will ask their own version of this. Paste your actual job description into the free Question Predictor and get the 20 questions that role is most likely to ask, with what each one is really probing.
Predict my questions