Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 5Objective 2

Threat Hunting CSA Practice Questions (Page 10)

Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.

49questions here
10free pages
10concepts

Questions 46–49

  1. 46foundation · easy

    What is the key difference between an Indicator of Attack (IOA) and an Indicator of Compromise (IOC)?

    Select an answer first
  2. 47application · medium

    An advanced persistent threat (APT) is known to use living-off-the-land binaries (LOLBins) like certutil.exe to download payloads. A SOC analyst wants to hunt for this activity in an environment where many legitimate administrative scripts also use certutil.exe. Which hunting approach would best reduce false positives while still detecting the APT?

    Select an answer first
  3. 48foundation · easy

    How does threat hunting differ from traditional security monitoring?

    Select an answer first
  4. 49foundation · easy

    What is the primary goal of threat hunting in a SOC environment?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.