Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 5Objective 2

Threat Hunting CSA Practice Questions (Page 2)

Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.

49questions here
10free pages
10concepts

Questions 6–10

  1. 6application · medium

    A SOC analyst at a financial firm notices a spike in outbound DNS queries to a domain recently flagged by threat intelligence as a C2 infrastructure. The analyst wants to proactively search for any hosts that may have communicated with this domain before the intelligence was published. Which approach best aligns with hypothesis-driven threat hunting?

    Select an answer first
  2. 7foundation · easy

    What does the acronym TTP stand for in the context of threat hunting?

    Select an answer first
  3. 8foundation · easy

    Which of the following is an example of an Indicator of Attack (IOA)?

    Select an answer first
  4. 9application · medium

    A SOC team is planning a hunt for data exfiltration by an insider threat. The hunt must detect large, unusual outbound transfers without relying on endpoint agents. Which data source combination would be most effective for this hunt?

    Select an answer first
  5. 10expert · hard

    A SOC team has completed a hunt that identified a new malware variant. The team wants to ensure that the findings are useful for future hunts and for improving detection. Which action would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.