
EC-CouncilCertified SOC Analyst
Domain 6Objective 2
Forensic Investigation and Malware Analysis CSA Practice Questions (Page 9)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
55questions here
11free pages
10concepts
Questions 41–45
- 41
A memory dump from a compromised server shows a suspicious process that has injected code into another legitimate process. Which memory forensics technique is most effective for confirming the injection?
Select an answer first - 42
During static analysis, an analyst uses a disassembler to view the assembly code of a malware sample. The analyst notices a sequence of `int 2dh` instructions. What is the most likely purpose of this sequence?
Select an answer first - 43
A SOC analyst is responding to a suspected breach in a Kubernetes cluster running on a cloud provider. Which log source is most likely to reveal the initial access vector?
Select an answer first - 44
During a cloud incident, the SOC team needs to identify which user or API key performed a specific action in an Azure subscription. Which log source is the most direct and reliable for this purpose?
Select an answer first - 45
A SOC analyst is about to start a forensic investigation on a laptop that was used to access a cloud service. The laptop is still running. Which action should the analyst take first to preserve volatile evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.