
EC-CouncilCertified SOC Analyst
Domain 6Objective 2
Forensic Investigation and Malware Analysis CSA Practice Questions (Page 11)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
55questions here
11free pages
10concepts
Questions 51–55
- 51
When performing disk forensics, which of the following is the primary reason for creating a forensic image of a hard drive?
Select an answer first - 52
A SOC analyst is responding to a security incident in a Kubernetes cluster running on AWS EKS. The analyst needs to collect evidence of a compromised pod. Which source is most useful for identifying what the attacker did inside the pod?
Select an answer first - 53
A malware sample behaves differently when run in a sandbox compared to a real user environment. The analyst suspects the malware detects virtualized environments. Which dynamic analysis approach is most likely to bypass this evasion and reveal the malware's true behavior?
Select an answer first - 54
When collecting evidence from a cloud environment, why is it important to consider the data's physical location?
Select an answer first - 55
An incident responder is collecting evidence from a compromised server. Which action best preserves the chain of custody?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.