Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 2

Forensic Investigation and Malware Analysis CSA Practice Questions (Page 5)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

55questions here
11free pages
10concepts

Questions 21–25

  1. 21expert · hard

    A SOC analyst is investigating a data exfiltration incident. The analyst has a PCAP file and needs to determine if sensitive data was sent over the network. The traffic is encrypted with TLS. Which approach is most effective?

    Select an answer first
  2. 22foundation · easy

    A network forensic analyst is reviewing a packet capture from a suspected intrusion. Which type of information is most directly obtained from analyzing network traffic?

    Select an answer first
  3. 23application · medium

    A company uses AWS for a critical application. During an incident, the SOC team needs to collect forensic evidence from an EC2 instance. The instance is still running. Which step is most appropriate to preserve evidence while minimizing disruption?

    Select an answer first
  4. 24application · medium

    A malware analyst has a suspicious file that is a Windows executable. The analyst wants to determine if the file is malicious without executing it. Which technique is most appropriate?

    Select an answer first
  5. 25foundation · easy

    During a cloud incident response, which log source is most likely to provide information about API calls made to cloud resources?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.