
EC-CouncilCertified SOC Analyst
Domain 2Objective 2
Indicators of Compromise (IoCs) CSA Practice Questions (Page 2)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
45questions here
9free pages
10concepts
Questions 6–10
- 6
Why do IoCs have a short lifespan in many cases?
Select an answer first - 7
A SOC analyst is reviewing a threat intelligence report that describes a new attack campaign. The report includes the following: a malicious IP address, a file hash, and a description of the attacker using PowerShell to download and execute the payload. The analyst wants to create a detection rule that will remain effective even if the attacker changes the IP and file hash. Which part of the report should the analyst focus on?
Select an answer first - 8
During incident response, a SOC team identifies a file hash and a C2 domain as IoCs. The team needs to eradicate the threat from the environment. Which action is most appropriate for eradication?
Select an answer first - 9
How can sandbox analysis contribute to the collection of Indicators of Compromise (IoCs)?
Select an answer first - 10
What is the primary purpose of an Indicator of Compromise (IoC) in a security operations context?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.