Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 2

Indicators of Compromise (IoCs) CSA Practice Questions (Page 1)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

45questions here
9free pages
10concepts

Questions 1–5

  1. 1foundation · easy

    Which of the following is a common source for gathering Indicators of Compromise (IoCs)?

    Select an answer first
  2. 2application · medium

    A SOC analyst is analyzing an IoC that is a domain name. The analyst wants to determine if the domain is malicious. Which additional information would be most useful for this analysis?

    Select an answer first
  3. 3foundation · easy

    What is a common limitation of IoCs?

    Select an answer first
  4. 4foundation · easy

    Which of the following is an example of a file-based Indicator of Compromise (IoC)?

    Select an answer first
  5. 5application · medium

    A SOC analyst is reviewing a threat intelligence report about a new ransomware family. The report lists the file hash of the ransomware binary, the C2 domain it uses, and a description of how it uses scheduled tasks for persistence. The analyst needs to configure immediate detection for this threat. Which item from the report should the analyst prioritize for a SIEM detection rule?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.