Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 3

Attacker Methodology and Cyber Kill Chain CSA Practice Questions (Page 7)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

49questions here
10free pages
11concepts

Questions 31–35

  1. 31expert · hard · select all that apply

    A SOC analyst is reviewing logs from a compromised Windows host. Which of the following are indicators of compromise (IoCs) that would be associated with the Exploitation and Installation phases of the kill chain? Select all that apply.

    Select an answer first
  2. 32application · medium · select all that apply

    A SOC analyst is reviewing network traffic for indicators of compromise (IoCs). Which of the following are IoCs that could indicate the Command and Control (C2) phase? (Select all that apply.)

    Select an answer first
  3. 33foundation · easy

    What is the primary purpose of active reconnaissance?

    Select an answer first
  4. 34foundation · easy

    In the Lockheed Martin Cyber Kill Chain, which phase involves the attacker creating a malicious payload tailored to exploit a specific vulnerability?

    Select an answer first
  5. 35application · medium

    An analyst discovers a malicious document attached to a phishing email. The document contains an embedded macro that, when executed, downloads a second-stage payload from a URL. In which kill chain phase does the macro execution occur, and what is the primary IoC to look for in the email gateway logs?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.