
EC-CouncilCertified SOC Analyst
Domain 2Objective 3
Attacker Methodology and Cyber Kill Chain CSA Practice Questions (Page 7)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
49questions here
10free pages
11concepts
Questions 31–35
- 31
A SOC analyst is reviewing logs from a compromised Windows host. Which of the following are indicators of compromise (IoCs) that would be associated with the Exploitation and Installation phases of the kill chain? Select all that apply.
Select an answer first - 32
A SOC analyst is reviewing network traffic for indicators of compromise (IoCs). Which of the following are IoCs that could indicate the Command and Control (C2) phase? (Select all that apply.)
Select an answer first - 33
What is the primary purpose of active reconnaissance?
Select an answer first - 34
In the Lockheed Martin Cyber Kill Chain, which phase involves the attacker creating a malicious payload tailored to exploit a specific vulnerability?
Select an answer first - 35
An analyst discovers a malicious document attached to a phishing email. The document contains an embedded macro that, when executed, downloads a second-stage payload from a URL. In which kill chain phase does the macro execution occur, and what is the primary IoC to look for in the email gateway logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.