
EC-CouncilCertified SOC Analyst
Domain 2Objective 2
Indicators of Compromise (IoCs) CSA Practice Questions (Page 5)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
45questions here
9free pages
10concepts
Questions 21–25
- 21
In the cyber kill chain, which stage is most likely to produce an IoC such as a suspicious email attachment?
Select an answer first - 22
A SOC analyst is analyzing a set of IoCs from a recent incident. The IoCs include a file hash, a domain, and an IP address. The analyst needs to determine the severity and relevance of these IoCs to the organization. Which approach would provide the most accurate assessment?
Select an answer first - 23
Which method is commonly used to collect IoCs from network traffic?
Select an answer first - 24
When analyzing an IoC, what does 'relevance' refer to?
Select an answer first - 25
A SOC team wants to enrich its detection capabilities with IoCs for a newly discovered ransomware family. The team has access to a commercial threat intelligence feed, a sandbox environment, and internal incident reports. Which approach would provide the most comprehensive and actionable IoCs for this ransomware?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.