Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 2

Forensic Investigation and Malware Analysis CSA Practice Questions (Page 11)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

55questions here
11free pages
10concepts

Questions 51–55

  1. 51foundation · easy

    When performing disk forensics, which of the following is the primary reason for creating a forensic image of a hard drive?

    Select an answer first
  2. 52application · medium

    A SOC analyst is responding to a security incident in a Kubernetes cluster running on AWS EKS. The analyst needs to collect evidence of a compromised pod. Which source is most useful for identifying what the attacker did inside the pod?

    Select an answer first
  3. 53expert · hard

    A malware sample behaves differently when run in a sandbox compared to a real user environment. The analyst suspects the malware detects virtualized environments. Which dynamic analysis approach is most likely to bypass this evasion and reveal the malware's true behavior?

    Select an answer first
  4. 54foundation · easy

    When collecting evidence from a cloud environment, why is it important to consider the data's physical location?

    Select an answer first
  5. 55foundation · easy

    An incident responder is collecting evidence from a compromised server. Which action best preserves the chain of custody?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.