
EC-CouncilCertified SOC Analyst
Domain 6Objective 2
Forensic Investigation and Malware Analysis CSA Practice Questions (Page 10)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
55questions here
11free pages
10concepts
Questions 46–50
- 46
A SOC analyst is analyzing a memory dump from a compromised server. The analyst suspects a rootkit that hides processes. Which technique is most effective for detecting hidden processes in memory?
Select an answer first - 47
A SOC analyst is collecting evidence from a compromised workstation. The analyst needs to ensure the evidence is admissible in court. Which practice is most important to maintain the chain of custody?
Select an answer first - 48
A malware analyst is given a suspicious document file that is believed to contain a macro-based dropper. The analyst wants to understand the dropper's behavior without executing the document on a production system. Which approach is most appropriate?
Select an answer first - 49
During an incident, a SOC analyst collects a hard drive image and a memory dump. The analyst needs to preserve the evidence for potential litigation. Which procedure is most critical to maintain the chain of custody?
Select an answer first - 50
A SOC analyst is collecting evidence from a cloud-based email service for a legal investigation. The organization is subject to data residency regulations. Which action is most important to ensure the evidence is admissible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.