Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 2

Indicators of Compromise (IoCs) CSA Practice Questions (Page 9)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

45questions here
9free pages
10concepts

Questions 41–45

  1. 41foundation · easy

    Why are TTPs considered more valuable than IoCs in long-term threat intelligence?

    Select an answer first
  2. 42foundation · easy

    Which of the following is categorized as an email artifact IoC?

    Select an answer first
  3. 43foundation · easy

    Which of the following is a method for collecting IoCs from endpoint data?

    Select an answer first
  4. 44application · medium

    During an incident investigation, a SOC analyst identifies a suspicious executable that was downloaded from a URL, then later observed beaconing to an external IP address. The analyst wants to create detection rules that cover the earliest possible stage of the attack lifecycle. Which IoC should the analyst prioritize for detection?

    Select an answer first
  5. 45expert · hard

    A SOC team is building a threat intelligence program. They have access to open-source feeds, a commercial feed, and internal telemetry. They need to decide which source to use for a specific detection use case: detecting a newly emerging malware family that is not yet widely known. Which source would be most valuable for this use case?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.