Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 1

Incident Response Process CSA Practice Questions (Page 8)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

56questions here
12free pages
9concepts

Questions 36–40

  1. 36application · medium

    A SOC analyst receives three alerts simultaneously: (1) a single workstation detected a known malware signature, (2) a domain admin account failed login 10 times in 5 minutes from a foreign IP, and (3) a database server is sending large outbound data volumes to an unknown IP. The analyst must prioritize. Which incident should be handled first?

    Select an answer first
  2. 37application · medium

    A SOC team has confirmed that a worm is spreading across the internal network via an unpatched SMB vulnerability. The team needs to stop the spread while preserving evidence for analysis. Which action should be taken first?

    Select an answer first
  3. 38application · medium

    After a phishing incident that compromised several user accounts, the SOC team has completed containment and eradication. The incident manager is preparing the post-incident report. Which element is most important to include for improving future response?

    Select an answer first
  4. 39application · medium

    After a security incident is resolved, the incident response team is preparing the final report. Which element is MOST important to include to help prevent future incidents?

    Select an answer first
  5. 40application · medium

    A SOC analyst is analyzing a memory dump from a compromised server. The analyst wants to identify the malicious process and its associated network connections. Which technique is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.