Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 3

Attacker Methodology and Cyber Kill Chain CSA Practice Questions (Page 8)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

49questions here
10free pages
11concepts

Questions 36–40

  1. 36expert · hard

    A SOC team is mapping an incident to MITRE ATT&CK. The attacker used a spear-phishing email with a malicious link to gain initial access, then used a PowerShell script to download and execute a payload, and finally established persistence by creating a registry run key. Which ATT&CK tactics correspond to the kill chain phases of Delivery, Exploitation, and Installation, respectively?

    Select an answer first
  2. 37application · medium

    A security analyst discovers a malicious document attached to a phishing email. The document contains an embedded macro that, when executed, downloads a second-stage payload from a remote server. In the Cyber Kill Chain, which phase does the macro execution represent?

    Select an answer first
  3. 38foundation · easy

    Which of the following is a potential indicator of compromise (IoC) associated with the reconnaissance phase of the Cyber Kill Chain?

    Select an answer first
  4. 39foundation · easy

    In the Cyber Kill Chain, what occurs during the exploitation phase?

    Select an answer first
  5. 40application · medium

    A SOC analyst is reviewing firewall logs and notices repeated DNS queries to a domain that was registered three days ago and has no associated web content. The queries originate from a single internal host and occur every 10 minutes. Which kill chain phase does this activity most likely represent, and what should the analyst do first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.