
EC-CouncilCertified SOC Analyst
Domain 2Objective 3
Attacker Methodology and Cyber Kill Chain CSA Practice Questions (Page 10)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
49questions here
10free pages
11concepts
Questions 46–49
- 46
A SOC analyst is mapping an incident to MITRE ATT&CK. The attacker used a compromised credential to access a VPN, then used PowerShell to download and execute a payload, and finally established a C2 channel. Which ATT&CK tactic corresponds to the 'Command and Control' phase of the Cyber Kill Chain?
Select an answer first - 47
A SOC analyst is explaining the Cyber Kill Chain to a new team member. The analyst describes a scenario where an attacker first scans the network for open ports, then sends a phishing email with a malicious attachment, and finally exfiltrates data. Which sequence of kill chain phases is correct?
Select an answer first - 48
Which of the following is the most accurate description of the general phases of a cyber attacker's methodology?
Select an answer first - 49
A SOC analyst is reviewing an alert for a web application. The log shows a series of requests to a login page with different usernames and passwords. The requests originate from a single IP address and occur over a short period. No successful login has occurred. Which kill chain phase is the analyst most likely observing?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.