
EC-CouncilCertified SOC Analyst
Domain 5Objective 2
Threat Hunting CSA Practice Questions (Page 2)
Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.
49questions here
10free pages
10concepts
Questions 6–10
- 6
A SOC analyst at a financial firm notices a spike in outbound DNS queries to a domain recently flagged by threat intelligence as a C2 infrastructure. The analyst wants to proactively search for any hosts that may have communicated with this domain before the intelligence was published. Which approach best aligns with hypothesis-driven threat hunting?
Select an answer first - 7
What does the acronym TTP stand for in the context of threat hunting?
Select an answer first - 8
Which of the following is an example of an Indicator of Attack (IOA)?
Select an answer first - 9
A SOC team is planning a hunt for data exfiltration by an insider threat. The hunt must detect large, unusual outbound transfers without relying on endpoint agents. Which data source combination would be most effective for this hunt?
Select an answer first - 10
A SOC team has completed a hunt that identified a new malware variant. The team wants to ensure that the findings are useful for future hunts and for improving detection. Which action would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.