▸case-05 We are establishing MTA-STS (Mail Transfer Agent Strict Transport Security) for our corporate email domain to force TLS encryption for incoming SMTP connections. How do we publish the MTA-STS DNS record and hosted policy file? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 I need to write an internal engineering playbook for implementing behavioral analysis and natural language processing to protect our cloud email platform against social engineering attacks. Can you lay out the systematic sequence of steps required from initial API integration up through SOAR workflow integration? Output this as a structured technical guide detailing the core phases of setup and validation. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 An internal employee's M365 account credentials were stolen, and the account is now sending internal phishing emails. How does behavioral AI detect account compromise when the email comes from a valid internal email address? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 When benchmarking BERT-based models against standard social engineering datasets for BEC identification, what accuracy benchmark is established? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-23 When connecting cloud email platforms like Microsoft 365 or Google Workspace to an AI security platform without deploying an MX record relay, which interfaces or APIs are utilized? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 How does the AI email security architecture extend behavioral threat detection to external business partners and supply chain vendors? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 We are experiencing an increase in vendor payment change requests and supply chain impersonation attempts targeting our finance department. I need a procedural document outlining how to establish baseline communication patterns, train text models, and set up tiered incident mitigation for anomalous messages. Please present this as a structured operational guide broken down into distinct sequence stages. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 How should an AI email security platform detect executive impersonation when an attacker sends an email from a external Gmail address using the CEO's display name without any malicious link or attachment? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 After SOC analysts review and verify BEC alerts, how should the verdicts be integrated back into the AI platform to continuously improve detection accuracy? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 An attacker creates a domain acme-paymen1s.com to impersonate a legitimate vendor and requests an urgent bank account update. How does AI behavioral detection identify this attack vector? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 We need to create static YARA signatures to detect compiled Windows PE executable attachments (.exe files) coming through our perimeter email gateway. What YARA condition syntax and magic header bytes should be used for detecting portable executable attachments? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 When evaluating incoming messages using NLP, what specific baseline intent classifications should the model output to categorize social engineering requests? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 We are deploying an API-driven email security platform connected to Microsoft 365. The engineering team proposes letting the platform observe email traffic for 2 weeks before enabling policy enforcement, but wants to know the minimum required duration for initial baseline learning. What initial learning window duration should be configured? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 Our SOC is reviewing our email authentication posture to prevent external domain spoofing. We need a guide on creating DNS records for SPF, DKIM, and DMARC enforcement. How should we format these DNS TXT records to publish strict rejection policies? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 In our behavioral baseline setup, we want to prevent false positives when finance or HR send legitimate internal requests. How should the platform map and baseline typical request types per organizational role? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 Our executive board requires strict SLAs before enabling automated email blocking. What maximum false positive rate threshold should be achieved after initial baseline training? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 Beyond message text and sentiment, what non-content email metadata attributes must be baselined to catch compromised account activity or anomalous logins? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 Before connecting an API-based behavioral email security solution to Google Workspace, our team needs to know how much historical email data must be present in user mailboxes for baseline training. Should we archive 1 year of PST backups or is a shorter historical window sufficient? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 When setting up NLP-based user profiling for executive communication monitoring, what specific stylistic and behavioral features should be baselined for each individual user rather than using organization-wide keywords? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 Our threat engineering team is choosing between traditional keyword regex pattern matching and modern natural language processing models for detecting linkless social engineering emails. Which deep learning model architecture should be deployed for email content analysis? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 We are configuring response actions in Microsoft Defender for Office 365 based on AI threat confidence levels. We do not want to block every medium-risk message outright. What tiered automated mitigation actions should be mapped to high, moderate, and low/review confidence levels? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 When justifying the deployment of API-based AI email security to leadership, what minimum performance improvement percentage over traditional keyword-based rules should be expected for phishing identification? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 Where in the email routing pipeline should API-based AI email security be integrated, and which traffic flows must be scanned beyond inbound internet mail? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |