Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 1

Incident Response Process CSA Practice Questions (Page 1)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

56questions here
12free pages
9concepts

Questions 1–5

  1. 1application · medium

    A SOC analyst is investigating a data exfiltration incident. The analyst has firewall logs, proxy logs, and DNS logs. Which log source would provide the MOST direct evidence of the data being transferred?

    Select an answer first
  2. 2application · medium

    A SOC analyst is collecting evidence from a compromised server for a potential lawsuit. The analyst must ensure the evidence is admissible in court. Which practice is MOST critical?

    Select an answer first
  3. 3foundation · easy

    In cloud incident response, what does the shared responsibility model primarily determine?

    Select an answer first
  4. 4application · medium

    An analyst is analyzing a memory dump from a compromised Windows system. Which artifact would provide the STRONGEST evidence of a previously running process that has since exited?

    Select an answer first
  5. 5application · medium

    A SOC analyst is investigating a suspected malware infection on a Windows workstation. The analyst has a memory dump and a disk image. Which artifact would provide the STRONGEST evidence of the malware's network command-and-control (C2) communication?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.