
EC-CouncilCertified SOC Analyst
Domain 6Objective 2
Forensic Investigation and Malware Analysis CSA Practice Questions (Page 2)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
55questions here
11free pages
10concepts
Questions 6–10
- 6
In cloud forensics, which factor primarily determines the types of evidence that can be collected by the customer?
Select an answer first - 7
A SOC analyst is reviewing network logs and notices that a compromised host is communicating with an IP address on port 445 (SMB) to an external IP. The analyst suspects data exfiltration. Which additional evidence would most strongly support this hypothesis?
Select an answer first - 8
A malware sample is compressed and encrypted to hide its true code. What is this technique called?
Select an answer first - 9
During static analysis of a suspicious binary, an analyst extracts readable text strings. What is the primary purpose of examining these strings?
Select an answer first - 10
What is the typical first step in a malware analysis workflow?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.