
EC-CouncilCertified SOC Analyst
Domain 6Objective 1
Incident Response Process CSA Practice Questions (Page 10)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
56questions here
12free pages
9concepts
Questions 46–50
- 46
Which classification would a SOC analyst most likely assign to an incident involving unauthorized access to a database containing sensitive customer data?
Select an answer first - 47
An incident responder needs to create a forensic image of a suspect's hard drive. The drive is connected to a write-blocker. Which hashing algorithm should be used to verify the integrity of the image?
Select an answer first - 48
A company experiences a security incident involving a cloud-hosted database. The company needs to preserve evidence for a legal investigation, but the cloud provider's shared responsibility model limits the company's access to the underlying infrastructure. Which action is most appropriate?
Select an answer first - 49
During an incident investigation, an analyst collects a forensic image of a laptop. The analyst needs to document the chain of custody. Which information is essential to record?
Select an answer first - 50
A company uses AWS for its production workloads. A security alert indicates that an EC2 instance may be compromised. The incident response team needs to acquire forensic evidence. What is the FIRST step the team should take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.