Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 2

Forensic Investigation and Malware Analysis CSA Practice Questions (Page 9)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

55questions here
11free pages
10concepts

Questions 41–45

  1. 41application · medium

    A memory dump from a compromised server shows a suspicious process that has injected code into another legitimate process. Which memory forensics technique is most effective for confirming the injection?

    Select an answer first
  2. 42application · medium

    During static analysis, an analyst uses a disassembler to view the assembly code of a malware sample. The analyst notices a sequence of `int 2dh` instructions. What is the most likely purpose of this sequence?

    Select an answer first
  3. 43application · medium

    A SOC analyst is responding to a suspected breach in a Kubernetes cluster running on a cloud provider. Which log source is most likely to reveal the initial access vector?

    Select an answer first
  4. 44application · medium

    During a cloud incident, the SOC team needs to identify which user or API key performed a specific action in an Azure subscription. Which log source is the most direct and reliable for this purpose?

    Select an answer first
  5. 45application · medium

    A SOC analyst is about to start a forensic investigation on a laptop that was used to access a cloud service. The laptop is still running. Which action should the analyst take first to preserve volatile evidence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.