
EC-CouncilCertified SOC Analyst
Domain 6Objective 2
Forensic Investigation and Malware Analysis CSA Practice Questions (Page 1)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
55questions here
11free pages
10concepts
Questions 1–5
- 1
A company uses a SaaS application for HR data. During an incident, the SOC team needs to collect evidence of unauthorized access to employee records. The SaaS provider offers limited logging. Which action is most appropriate to preserve evidence while respecting the shared responsibility model?
Select an answer first - 2
A company's web server was compromised. Network logs show outbound HTTPS connections to an IP address that is now offline. The analyst has a pcap file from the time of the incident, but the traffic is encrypted. Which approach is most likely to reveal the command-and-control (C2) communication content?
Select an answer first - 3
During a cloud incident in Microsoft 365, a SOC analyst needs to determine if a user's account was compromised and what actions the attacker performed. Which log source is most critical to enable and review?
Select an answer first - 4
A SOC analyst is reviewing network traffic from a compromised host. The analyst sees repeated DNS queries to a domain that resolves to different IP addresses every few minutes. The host also communicates with those IPs on port 443 using TLS. Which finding best supports a hypothesis of malware command-and-control (C2) activity?
Select an answer first - 5
A malware analyst wants to understand the behavior of a suspicious executable without executing it. Which type of malware analysis is this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.