
EC-CouncilCertified SOC Analyst
Domain 5Objective 2
Threat Hunting CSA Practice Questions (Page 1)
Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.
49questions here
10free pages
10concepts
Questions 1–5
- 1
A threat intelligence feed provides a list of file hashes associated with a new ransomware strain. The SOC wants to proactively determine if any of these hashes exist in the environment. Which approach is most effective for this hunt?
Select an answer first - 2
An organization has seen a rise in phishing emails that contain malicious macros. The SOC wants to proactively hunt for any hosts that may have executed macros from such emails, even if the payload was later deleted. Which hunting technique would be most effective?
Select an answer first - 3
Which of the following is a hunting approach specifically for detecting insider threats?
Select an answer first - 4
A SOC analyst is planning a hunt for credential dumping. The analyst has access to Windows Security logs, Sysmon logs, and network flow logs. Which sequence of steps best follows the systematic threat hunting process?
Select an answer first - 5
Why is knowledge of adversary TTPs valuable for threat hunting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.