
EC-CouncilCertified SOC Analyst
Domain 2Objective 3
Attacker Methodology and Cyber Kill Chain CSA Practice Questions (Page 3)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
49questions here
10free pages
11concepts
Questions 11–15
- 11
Which of the following is a common method used by attackers to deliver a malicious payload to a target?
Select an answer first - 12
During an investigation, you find that a compromised host is using HTTP requests to a legitimate-looking website to receive commands. The requests are formatted as normal web traffic and occur at random intervals. What is the most likely purpose of this behavior, and which IoC would be most useful for detection?
Select an answer first - 13
Which of the following is an example of exploitation?
Select an answer first - 14
During an incident response, you discover that an attacker has been exfiltrating data from a database server over the past two weeks. The exfiltration uses the same C2 channel that was established after the initial compromise. The attacker has also deleted some logs on the server. Which action should you take FIRST to preserve evidence and stop further data loss?
Select an answer first - 15
In the context of attacker methodology, which statement best describes the typical mindset of a cyber attacker?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.