Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 3

Attacker Methodology and Cyber Kill Chain CSA Practice Questions (Page 9)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

49questions here
10free pages
11concepts

Questions 41–45

  1. 41foundation · easy

    Which MITRE ATT&CK tactic corresponds most closely to the 'installation' phase of the Cyber Kill Chain?

    Select an answer first
  2. 42foundation · easy

    Why do attackers focus on establishing persistence during the installation phase?

    Select an answer first
  3. 43application · medium

    A SOC analyst is analyzing a malicious document that was delivered via email. The document contains an embedded object that, when opened, downloads a PowerShell script from a remote server. In the Cyber Kill Chain, which phase is the creation of the malicious document?

    Select an answer first
  4. 44application · medium

    An attacker creates a malicious PDF file that exploits a known vulnerability in a PDF reader and sends it as an email attachment to employees in the finance department. Which two kill chain phases are represented by the creation of the PDF and the sending of the email, respectively?

    Select an answer first
  5. 45application · medium

    A SOC team is investigating an incident where an attacker exploited an unpatched vulnerability in a public-facing web application to upload a web shell. According to the Lockheed Martin Cyber Kill Chain, which phase does the web shell upload represent, and how does this map to MITRE ATT&CK?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.