
EC-CouncilCertified SOC Analyst
Domain 6Objective 2
Forensic Investigation and Malware Analysis CSA Practice Questions (Page 3)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
55questions here
11free pages
10concepts
Questions 11–15
- 11
A malware analyst is tasked with analyzing a new ransomware sample. The analyst wants to understand the malware's behavior without risking infection of the production network. Which of the following are appropriate steps in the malware analysis process? Select all that apply.
Select an answer first - 12
Which malware evasion technique is specifically designed to detect if a debugger is attached to the process?
Select an answer first - 13
Which of the following is a key difference between incident response in a traditional on-premises environment and a cloud environment?
Select an answer first - 14
A memory dump from an infected workstation contains a suspicious process that is hidden from the normal process list. The analyst suspects rootkit functionality. Which memory forensics technique would most directly reveal the hidden process?
Select an answer first - 15
A SOC analyst receives a suspicious executable file from an employee. The analyst needs to determine the file's purpose without risking infection of the corporate network. Which sequence of actions is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.