Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 4Objective 3

Alert Triaging and Analysis CSA Practice Questions (Page 5)

Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.

35questions here
7free pages
7concepts

Questions 21–25

  1. 21expert · hard

    A SOC sees 100 alerts for outbound connections to a single IP address from 50 different workstations. The IP is a known file-sharing service. The alerts are all identical in nature. The analyst has limited time. What is the most efficient and effective approach?

    Select an answer first
  2. 22application · medium

    A junior analyst is overwhelmed by the number of alerts and asks a senior analyst for advice on how to manage the workload. What is the most effective advice the senior analyst can give?

    Select an answer first
  3. 23application · easy

    A new SOC analyst asks why the team spends time triaging alerts instead of immediately responding to every one. What is the primary reason for the triage process?

    Select an answer first
  4. 24application · medium

    An alert fires for 'Suspicious outbound connection' from a server that hosts a legacy application. The destination IP is in a country where the company has no operations. The analyst checks the server's documentation and finds that the legacy application is supposed to connect to a vendor service for license validation, but the vendor's IP range is different from the destination. What should the analyst do?

    Select an answer first
  5. 25foundation · easy

    Why is it important to document the rationale for closing an alert as a false positive?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.