
EC-CouncilCertified SOC Analyst
Domain 2Objective 2
Indicators of Compromise (IoCs) CSA Practice Questions (Page 7)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
45questions here
9free pages
10concepts
Questions 31–35
- 31
A SOC analyst is triaging a list of IoCs from an open-source threat feed. The list includes a file hash, a domain, and an IP address. The analyst needs to prioritize which IoCs to investigate first. Which factor should be the primary consideration when prioritizing these IoCs?
Select an answer first - 32
During an incident, a SOC analyst identifies a malicious domain that is being used for C2. The analyst wants to integrate this IoC into the incident response process. Which step should the analyst take to support containment?
Select an answer first - 33
What is the primary difference between an Indicator of Compromise (IoC) and a Tactic, Technique, or Procedure (TTP)?
Select an answer first - 34
A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an internal host is communicating with an external IP address on a non-standard port. Which data source would provide the most direct evidence of the communication?
Select an answer first - 35
A threat intelligence analyst is writing a report about an advanced persistent threat (APT) group. The analyst has identified several IoCs and also observed the group's TTPs. Which statement correctly explains why TTPs are often considered more valuable than IoCs for long-term defense?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.