Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 2

Forensic Investigation and Malware Analysis CSA Practice Questions (Page 8)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

55questions here
11free pages
10concepts

Questions 36–40

  1. 36expert · hard

    A SOC analyst is analyzing a memory dump and finds an anomalous process that is not visible in the process list but is present in the memory's kernel structures. The analyst suspects a kernel-level rootkit. Which tool or technique is most effective for further investigation?

    Select an answer first
  2. 37foundation · easy

    During an incident response engagement, a forensic investigator is about to begin collecting evidence from a compromised workstation. Which principle should guide the investigator's actions to ensure the evidence remains admissible in legal proceedings?

    Select an answer first
  3. 38foundation · easy

    A SOC analyst is preparing to conduct forensic analysis as part of an incident response. Which legal consideration is most important when handling evidence that may be used in a prosecution?

    Select an answer first
  4. 39foundation · easy

    Which network forensic technique is used to reconstruct the sequence of events during an attack?

    Select an answer first
  5. 40foundation · easy

    A malware analyst is executing a suspicious sample in a controlled environment to observe its behavior. What is this process called?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.