Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 4Objective 3

Alert Triaging and Analysis CSA Practice Questions (Page 6)

Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.

35questions here
7free pages
7concepts

Questions 26–30

  1. 26foundation · easy

    When aggregating duplicate alerts, what is the main goal?

    Select an answer first
  2. 27application · medium

    A SOC analyst is reviewing an alert that fired when a finance workstation attempted to connect to a known malicious IP address. The alert is rated 'high' by the SIEM. The analyst checks the asset inventory and sees the workstation belongs to the CFO, who is currently traveling. The analyst also queries the threat intelligence platform and finds the IP is associated with a phishing campaign targeting executives. However, the connection was blocked by the firewall and no data was exfiltrated. What should the analyst do next?

    Select an answer first
  3. 28foundation · easy

    In a SOC workflow, what is the primary purpose of alert triage?

    Select an answer first
  4. 29application · medium

    A SOC receives three alerts: (1) a single failed login for a standard user, (2) a successful login from a foreign IP for a service account with MFA disabled, and (3) a malware signature hit on an isolated test VM. The analyst has limited time. Which alert should be handled first?

    Select an answer first
  5. 30foundation · easy

    What is the purpose of documenting triage findings in a structured format?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.