Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 2

Forensic Investigation and Malware Analysis CSA Practice Questions (Page 7)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

55questions here
11free pages
10concepts

Questions 31–35

  1. 31expert · hard

    A company's cloud environment has a suspected data exfiltration. The SOC team has access to VPC flow logs, DNS logs, and application logs. Which combination of logs is most effective for reconstructing the exfiltration path?

    Select an answer first
  2. 32foundation · easy

    Which tool is commonly used for static analysis of a Windows executable to view its imported functions and strings?

    Select an answer first
  3. 33application · medium

    A malware analyst receives a suspicious executable file. The analyst runs the `strings` command and finds a suspicious URL, but the file appears to be packed. What is the most appropriate next step in static analysis?

    Select an answer first
  4. 34application · medium

    During an incident response, a SOC analyst needs to collect a memory dump from a compromised Windows server. The server is running critical production services and cannot be powered off. Which action best preserves the integrity of the evidence while meeting the operational constraint?

    Select an answer first
  5. 35application · medium

    During static analysis of a malware sample, the analyst notices that the file has a very high entropy value and contains a section named `.UPX0`. What does this indicate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.