
EC-CouncilCertified SOC Analyst
Domain 6Objective 2
Forensic Investigation and Malware Analysis CSA Practice Questions (Page 8)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
55questions here
11free pages
10concepts
Questions 36–40
- 36
A SOC analyst is analyzing a memory dump and finds an anomalous process that is not visible in the process list but is present in the memory's kernel structures. The analyst suspects a kernel-level rootkit. Which tool or technique is most effective for further investigation?
Select an answer first - 37
During an incident response engagement, a forensic investigator is about to begin collecting evidence from a compromised workstation. Which principle should guide the investigator's actions to ensure the evidence remains admissible in legal proceedings?
Select an answer first - 38
A SOC analyst is preparing to conduct forensic analysis as part of an incident response. Which legal consideration is most important when handling evidence that may be used in a prosecution?
Select an answer first - 39
Which network forensic technique is used to reconstruct the sequence of events during an attack?
Select an answer first - 40
A malware analyst is executing a suspicious sample in a controlled environment to observe its behavior. What is this process called?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.