Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 1

Incident Response Process CSA Practice Questions (Page 5)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

56questions here
12free pages
9concepts

Questions 21–25

  1. 21expert · hard

    A SOC analyst is investigating a server that was compromised. The analyst has a memory dump and a disk image. The analyst wants to determine if a specific file was accessed by the attacker. Which approach is most effective?

    Select an answer first
  2. 22foundation · easy

    Which disk artifact is commonly examined to identify recently accessed files and folders on a Windows system?

    Select an answer first
  3. 23expert · hard

    A SOC analyst is reconstructing the timeline of a multi-stage attack. The analyst has logs from the firewall, the authentication server, and the endpoint detection and response (EDR) tool. The logs have different timestamp formats and time zones. Which action is most important for accurate timeline reconstruction?

    Select an answer first
  4. 24foundation · easy

    What is the primary purpose of correlating logs from multiple sources during incident response?

    Select an answer first
  5. 25expert · hard

    After a major security incident, the incident response team is conducting a post-incident review. The team has identified several areas for improvement. Which action is MOST important to ensure the improvements are implemented?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.