Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 2

Indicators of Compromise (IoCs) CSA Practice Questions (Page 3)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

45questions here
9free pages
10concepts

Questions 11–15

  1. 11foundation · easy

    During which phase of incident response are IoCs most commonly used to identify affected systems?

    Select an answer first
  2. 12application · medium

    A SOC team wants to detect a known malware campaign that uses a specific domain for C2 and a specific file hash for the dropper. They want to implement detection at multiple layers. Which combination of detection mechanisms would provide the most comprehensive coverage?

    Select an answer first
  3. 13expert · hard

    A SOC team is implementing detection for a new malware campaign. The campaign uses a unique file hash for the initial dropper, a domain for C2, and a specific pattern of DNS queries. The team wants to minimize false positives while maximizing detection. Which approach is most effective?

    Select an answer first
  4. 14foundation · easy

    Which of the following is a common way to use IoCs in an IDS/IPS?

    Select an answer first
  5. 15application · medium

    A SOC team is building a threat intelligence program and wants to collect IoCs from multiple sources. They have access to a commercial threat intelligence feed, internal incident reports, and a sandbox environment. The team wants to prioritize IoCs that are most relevant to their organization. Which approach should they take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.