
EC-CouncilCertified SOC Analyst
Domain 2Objective 2
Indicators of Compromise (IoCs) CSA Practice Questions (Page 4)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
45questions here
9free pages
10concepts
Questions 16–20
- 16
A SOC team wants to detect a known malware that uses a specific user-agent string in its HTTP requests. The team wants to implement detection at the network layer. Which detection mechanism should they use?
Select an answer first - 17
A SOC team is evaluating a new threat intelligence feed. The feed provides a list of file hashes and domains. The team wants to assess the feed's quality before integrating it into their SIEM. Which factor is most important to evaluate?
Select an answer first - 18
How are IoCs typically used in a SIEM to enhance detection?
Select an answer first - 19
A SOC team is reviewing a threat report that includes a file hash, a C2 domain, and a description of the attacker using a specific PowerShell command to enumerate Active Directory. The team wants to build a detection strategy that is resilient to the attacker changing their infrastructure. Which approach is most effective?
Select an answer first - 20
An analyst is mapping observed indicators to the Cyber Kill Chain. The analyst sees a suspicious outbound connection to an IP address that is known to be a command-and-control server. Which stage of the kill chain does this IoC most directly indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.