
EC-CouncilCertified SOC Analyst
Domain 5Objective 2
Threat Hunting CSA Practice Questions (Page 4)
Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.
49questions here
10free pages
10concepts
Questions 16–20
- 16
A SOC is hunting for a ransomware attack that may have used a legitimate remote management tool (RMM) for lateral movement. The team has limited log storage and must choose which data sources to prioritize for the hunt. Which data source combination would provide the best balance of coverage and storage efficiency?
Select an answer first - 17
During a hunt for data exfiltration, an analyst finds a series of events: a user downloads a large file from a SharePoint site, then uses a personal cloud storage app to upload it, and then deletes the local copy. The user has a history of legitimate large downloads. How should the analyst proceed?
Select an answer first - 18
A SOC team is tasked with hunting for an advanced persistent threat (APT) that is known to use fileless techniques and PowerShell for execution. The team has limited time and resources. Which hunting approach would be most efficient for detecting this APT?
Select an answer first - 19
A SOC analyst is hunting for signs of credential dumping on Windows endpoints. The analyst has access to Sysmon logs, Windows Event Logs, and EDR telemetry. Which combination of data sources and queries would be most effective for detecting credential dumping behavior?
Select an answer first - 20
Why are endpoint logs considered a critical data source for threat hunting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.