Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 3

Attacker Methodology and Cyber Kill Chain CSA Practice Questions (Page 6)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

49questions here
10free pages
11concepts

Questions 26–30

  1. 26foundation · easy

    Which of the following is a common technique used by attackers to maintain persistence on a compromised system?

    Select an answer first
  2. 27application · medium

    A SOC analyst is reviewing network logs and notices repeated DNS queries for subdomains that do not exist (e.g., random strings under a legitimate corporate domain). The queries originate from a single internal host and have been occurring for several hours. No malware has been detected on the host yet. According to the Cyber Kill Chain, which phase is the analyst most likely observing?

    Select an answer first
  3. 28foundation · easy

    Which of the following is an example of passive reconnaissance?

    Select an answer first
  4. 29application · medium

    An analyst notices a compromised host making periodic HTTPS connections to a domain that was registered only two days ago. The domain has no web content and is not in any threat intel feed. Which kill chain phase is the analyst most likely observing?

    Select an answer first
  5. 30application · medium

    After compromising a Linux server, an attacker adds a cron job that runs a reverse shell script every 10 minutes. The script connects to an external IP address. Which kill chain phase is the cron job addition?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.