
EC-CouncilCertified SOC Analyst
Domain 4Objective 3
Alert Triaging and Analysis CSA Practice Questions (Page 3)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
35questions here
7free pages
7concepts
Questions 11–15
- 11
An alert fires for 'Suspicious PowerShell execution' on a server that hosts a critical database. The analyst checks the process command line and sees a script that downloads a file from a public file-sharing site. The server's change-management system shows no approved maintenance for this server today. The file-sharing domain is not on any threat-intel blocklist. What should the analyst do?
Select an answer first - 12
After triaging an alert, an analyst determines it is a true positive and escalates it. What is the most important information to include in the escalation documentation?
Select an answer first - 13
A SOC analyst is investigating a series of alerts: a phishing email reported by a user, a subsequent login from a new device, and then a download of a suspicious file. The analyst notices that the login and download occurred within minutes of the user clicking the phishing link. What is the most appropriate action?
Select an answer first - 14
What is the primary benefit of correlating multiple related alerts during triage?
Select an answer first - 15
An alert fires for a user accessing a known phishing URL. The analyst checks the user's activity and finds the user clicked the link in a test email sent by the security team. What is the correct classification and action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.