
EC-CouncilCertified SOC Analyst
Domain 6Objective 2
Forensic Investigation and Malware Analysis CSA Practice Questions (Page 4)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
55questions here
11free pages
10concepts
Questions 16–20
- 16
A SOC analyst is collecting evidence from a compromised server. The analyst has already captured a memory dump and a disk image. What is the next step to ensure the evidence is preserved for later analysis?
Select an answer first - 17
During dynamic analysis, a malware sample detects that it is running inside a virtual machine and exits without performing its malicious actions. Which anti-analysis technique is the malware using?
Select an answer first - 18
A forensic analyst is examining a memory dump from a compromised system. Which type of information is most likely to be found ONLY in memory and not on disk?
Select an answer first - 19
A malware analyst is performing static analysis on a suspicious executable. The file's entropy is very high, and the section names are non-standard. What does this indicate?
Select an answer first - 20
A SOC analyst is handling an incident that involves data stored in a cloud service. The legal team requires that evidence be preserved in a forensically sound manner. The cloud provider's shared responsibility model means the customer is responsible for the data. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.