
EC-CouncilCertified SOC Analyst
Domain 6Objective 1
Incident Response Process CSA Practice Questions (Page 2)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
56questions here
12free pages
9concepts
Questions 6–10
- 6
An analyst is reconstructing the timeline of a breach. The analyst has the following logs: firewall logs showing outbound connections to a suspicious IP, DNS logs showing queries to a malicious domain, and Windows event logs showing a user login at 2:00 AM. Which sequence of events would BEST support the hypothesis that the breach started with a phishing email?
Select an answer first - 7
An analyst is acquiring a forensic image of a USB drive that was used by a suspected insider. The analyst wants to ensure the image is admissible in court. Which step is most important?
Select an answer first - 8
Which containment strategy is most appropriate for a malware infection that is actively spreading across the network?
Select an answer first - 9
A company has suffered a malware infection that has been contained. The malware is known to have created a scheduled task for persistence. Which step is part of the ERADICATION phase?
Select an answer first - 10
A SOC analyst is reconstructing the timeline of a security incident. The analyst has firewall logs, Windows Event Logs, and web proxy logs. Which approach best helps to reconstruct the incident timeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.