
EC-CouncilCertified SOC Analyst
Domain 2Objective 2
Indicators of Compromise (IoCs) CSA Practice Questions (Page 3)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
45questions here
9free pages
10concepts
Questions 11–15
- 11
During which phase of incident response are IoCs most commonly used to identify affected systems?
Select an answer first - 12
A SOC team wants to detect a known malware campaign that uses a specific domain for C2 and a specific file hash for the dropper. They want to implement detection at multiple layers. Which combination of detection mechanisms would provide the most comprehensive coverage?
Select an answer first - 13
A SOC team is implementing detection for a new malware campaign. The campaign uses a unique file hash for the initial dropper, a domain for C2, and a specific pattern of DNS queries. The team wants to minimize false positives while maximizing detection. Which approach is most effective?
Select an answer first - 14
Which of the following is a common way to use IoCs in an IDS/IPS?
Select an answer first - 15
A SOC team is building a threat intelligence program and wants to collect IoCs from multiple sources. They have access to a commercial threat intelligence feed, internal incident reports, and a sandbox environment. The team wants to prioritize IoCs that are most relevant to their organization. Which approach should they take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.