Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 3

Attacker Methodology and Cyber Kill Chain CSA Practice Questions (Page 10)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

49questions here
10free pages
11concepts

Questions 46–49

  1. 46application · medium

    A SOC analyst is mapping an incident to MITRE ATT&CK. The attacker used a compromised credential to access a VPN, then used PowerShell to download and execute a payload, and finally established a C2 channel. Which ATT&CK tactic corresponds to the 'Command and Control' phase of the Cyber Kill Chain?

    Select an answer first
  2. 47application · medium

    A SOC analyst is explaining the Cyber Kill Chain to a new team member. The analyst describes a scenario where an attacker first scans the network for open ports, then sends a phishing email with a malicious attachment, and finally exfiltrates data. Which sequence of kill chain phases is correct?

    Select an answer first
  3. 48foundation · easy

    Which of the following is the most accurate description of the general phases of a cyber attacker's methodology?

    Select an answer first
  4. 49expert · hard

    A SOC analyst is reviewing an alert for a web application. The log shows a series of requests to a login page with different usernames and passwords. The requests originate from a single IP address and occur over a short period. No successful login has occurred. Which kill chain phase is the analyst most likely observing?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.