
EC-CouncilCertified SOC Analyst
Domain 2Objective 2
Indicators of Compromise (IoCs) CSA Practice Questions (Page 6)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
45questions here
9free pages
10concepts
Questions 26–30
- 26
During incident response, a SOC analyst has identified a set of IoCs, including a malicious domain and a file hash. The incident response team needs to contain the threat. Which action should the analyst take first?
Select an answer first - 27
A SOC analyst is investigating a potential malware infection on a user's workstation. The analyst needs to collect IoCs from the endpoint to determine the scope of the infection. Which data source would provide the most direct evidence of the malware's execution and persistence?
Select an answer first - 28
How can IoCs be used during the containment phase of incident response?
Select an answer first - 29
Which of the following IoCs is most commonly associated with the 'Command and Control' stage of the cyber kill chain?
Select an answer first - 30
A SOC analyst is configuring an IDS with a list of malicious IP addresses from a threat feed. After a week, the analyst notices a high number of alerts, but most are false positives. What is the most likely reason for this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.