
EC-CouncilCertified SOC Analyst
Domain 2Objective 2
Indicators of Compromise (IoCs) CSA Practice Questions (Page 1)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
45questions here
9free pages
10concepts
Questions 1–5
- 1
Which of the following is a common source for gathering Indicators of Compromise (IoCs)?
Select an answer first - 2
A SOC analyst is analyzing an IoC that is a domain name. The analyst wants to determine if the domain is malicious. Which additional information would be most useful for this analysis?
Select an answer first - 3
What is a common limitation of IoCs?
Select an answer first - 4
Which of the following is an example of a file-based Indicator of Compromise (IoC)?
Select an answer first - 5
A SOC analyst is reviewing a threat intelligence report about a new ransomware family. The report lists the file hash of the ransomware binary, the C2 domain it uses, and a description of how it uses scheduled tasks for persistence. The analyst needs to configure immediate detection for this threat. Which item from the report should the analyst prioritize for a SIEM detection rule?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.