Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 1

Incident Response Process CSA Practice Questions (Page 11)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

56questions here
12free pages
9concepts

Questions 51–55

  1. 51foundation · easy

    In the incident response lifecycle, which phase involves removing the root cause of an incident from affected systems?

    Select an answer first
  2. 52foundation · easy

    Which challenge is unique to cloud forensics compared to traditional on-premises forensics?

    Select an answer first
  3. 53application · medium

    A SOC analyst is investigating a suspected memory-resident malware infection on a Windows workstation. The analyst needs to capture evidence that will reveal the malware's process, network connections, and loaded modules. Which action should the analyst take first?

    Select an answer first
  4. 54expert · hard

    A SOC analyst is correlating logs from multiple sources to identify a potential data exfiltration. The analyst has firewall logs, proxy logs, and DNS logs. Which correlation would provide the STRONGEST evidence of data exfiltration?

    Select an answer first
  5. 55foundation · easy

    Which tool is commonly used to create a forensic image of a disk while preserving the integrity of the original media?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.