Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 2

Forensic Investigation and Malware Analysis CSA Practice Questions (Page 4)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

55questions here
11free pages
10concepts

Questions 16–20

  1. 16application · medium

    A SOC analyst is collecting evidence from a compromised server. The analyst has already captured a memory dump and a disk image. What is the next step to ensure the evidence is preserved for later analysis?

    Select an answer first
  2. 17application · medium

    During dynamic analysis, a malware sample detects that it is running inside a virtual machine and exits without performing its malicious actions. Which anti-analysis technique is the malware using?

    Select an answer first
  3. 18foundation · easy

    A forensic analyst is examining a memory dump from a compromised system. Which type of information is most likely to be found ONLY in memory and not on disk?

    Select an answer first
  4. 19application · medium

    A malware analyst is performing static analysis on a suspicious executable. The file's entropy is very high, and the section names are non-standard. What does this indicate?

    Select an answer first
  5. 20expert · hard

    A SOC analyst is handling an incident that involves data stored in a cloud service. The legal team requires that evidence be preserved in a forensically sound manner. The cloud provider's shared responsibility model means the customer is responsible for the data. Which action is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.