
EC-CouncilCertified SOC Analyst
Domain 5Objective 2
Threat Hunting CSA Practice Questions (Page 10)
Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.
49questions here
10free pages
10concepts
Questions 46–49
- 46
What is the key difference between an Indicator of Attack (IOA) and an Indicator of Compromise (IOC)?
Select an answer first - 47
An advanced persistent threat (APT) is known to use living-off-the-land binaries (LOLBins) like certutil.exe to download payloads. A SOC analyst wants to hunt for this activity in an environment where many legitimate administrative scripts also use certutil.exe. Which hunting approach would best reduce false positives while still detecting the APT?
Select an answer first - 48
How does threat hunting differ from traditional security monitoring?
Select an answer first - 49
What is the primary goal of threat hunting in a SOC environment?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.