Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 4Objective 3

Alert Triaging and Analysis CSA Practice Questions (Page 1)

Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.

35questions here
7free pages
7concepts

Questions 1–5

  1. 1foundation · easy

    What is the purpose of enriching an alert with threat intelligence during triage?

    Select an answer first
  2. 2expert · hard

    A SOC has a rule that flags any login from a new geographic location. An analyst sees an alert for a C-level executive logging in from a country where the company has no offices. The executive is currently in a meeting in the headquarters building. The analyst has access to the executive's calendar and confirms the meeting. What should the analyst do?

    Select an answer first
  3. 3expert · hard

    A SOC analyst is investigating an alert for 'Suspicious outbound connection' from a workstation. The destination IP is a known malicious IP according to threat intelligence. The analyst checks the workstation's process list and sees that a legitimate application is making the connection. The application is a web browser that is open to a website that is not on any blocklist. The analyst also checks the DNS logs and sees that the workstation resolved a domain that is associated with the malicious IP. What should the analyst do?

    Select an answer first
  4. 4application · medium

    An analyst sees an alert for 'Abnormal PowerShell usage' on a developer workstation. The analyst checks the process tree and sees that PowerShell was launched by the user's IDE during a build process. The script is a known build script that has been used for months. The alert is triggered because the script uses the Invoke-WebRequest cmdlet to download dependencies. What should the analyst do?

    Select an answer first
  5. 5application · medium

    A SOC analyst is reviewing a dashboard that shows 50 low-severity alerts from the same subnet over the past hour. The alerts are for 'DNS query to suspicious domain' and each involves a different workstation. The analyst notices that all the workstations are in the marketing department and the domains are all recently registered. What should the analyst do first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.