Ran through the usual signals: sender address mismatches, suspicious links, urgency language, unexpected attachments.
Structure your answer around a systematic analysis of email artifacts, focusing on sender authenticity, content anomalies, and technical indicators. Emphasize how you would verify suspicions through independent channels and apply lessons learned to prevent future incidents, aligning with NASA's security-first culture.
Pro tip: Demonstrate maturity by acknowledging that even experienced engineers can be targeted, and emphasize the importance of reporting suspicious emails immediately rather than trying to investigate alone. Mention that you would follow NASA's specific incident response protocols, showing you understand organizational context.
Check the sender's email address for spoofing or domain misspellings, and examine email headers for inconsistencies in the 'From', 'Reply-To', and 'Return-Path' fields. Use tools like SPF, DKIM, and DMARC validation results if available.
Look for urgent or threatening language, generic greetings, requests for sensitive information, unexpected attachments, or links that don't match the displayed text. Hover over links to preview the actual URL.
If the email appears to come from a known contact, verify its legitimacy by contacting the person through a separate, trusted method (e.g., phone or internal chat) rather than replying to the email.
Check for mismatched URLs, suspicious domains, or attachments with unusual file extensions. Use sandboxing or virus total to analyze attachments or links if you have the tools and authorization.
Immediately report the email to your organization's security team (e.g., via a phishing report button or email to abuse@nasa.gov). If you interacted with it, follow incident response procedures to mitigate potential compromise.
AI-generated suggestions, not part of the candidate's original notes. May be inaccurate — verify before relying on them.