
EC-CouncilCertified SOC Analyst
Domain 1Objective 1
Security Operations Center (SOC) Fundamentals CSA Practice Questions (Page 9)
Part of the Security Operations and Management domain, which makes up ~12% of our current practice bank.
45questions here
9free pages
8concepts
Questions 41–45
- 41
A SOC analyst receives an alert from the SIEM about a possible brute-force attack on a user account. The analyst checks the logs and confirms that the attack is ongoing. According to the SOC's procedures, what should the analyst do next?
Select an answer first - 42
A SOC analyst is investigating a potential data exfiltration incident. The SIEM shows a large outbound data transfer from a server to an external IP. The analyst needs to confirm whether the transfer is malicious. Which combination of actions would provide the MOST reliable confirmation?
Select an answer first - 43
Which statement best defines a Security Operations Center (SOC)?
Select an answer first - 44
A SOC team is overwhelmed by a high volume of low-fidelity alerts from their SIEM, causing analysts to miss critical alerts. Which combination of tools and processes would BEST address this issue?
Select an answer first - 45
Which process is typically used in a SOC to ensure that alerts are systematically reviewed and resolved?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.