Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 1

Incident Response Process CSA Practice Questions (Page 3)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

56questions here
12free pages
9concepts

Questions 11–15

  1. 11foundation · easy

    Which type of analysis is most useful for detecting malware that exists only in a system's RAM and leaves no trace on the disk?

    Select an answer first
  2. 12foundation · easy

    What is the primary purpose of a post-incident review meeting?

    Select an answer first
  3. 13foundation · easy

    Which log source would provide the most direct evidence of an attacker attempting to authenticate to a server?

    Select an answer first
  4. 14application · medium

    After containing a ransomware incident, the SOC team needs to eradicate the threat and recover systems. Which action is most appropriate for eradication?

    Select an answer first
  5. 15expert · hard

    An incident responder is collecting evidence from a compromised server. The responder needs to maintain chain of custody for legal proceedings. The responder has already imaged the disk and captured memory. What is the NEXT step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.