Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 5Objective 2

Threat Hunting CSA Practice Questions (Page 5)

Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.

49questions here
10free pages
10concepts

Questions 21–25

  1. 21application · medium

    A threat intelligence feed provides a list of malicious IP addresses and file hashes associated with a recent campaign. A SOC analyst wants to proactively search the environment for any signs of this campaign. Which approach is most appropriate?

    Select an answer first
  2. 22foundation · easy

    Which of the following is an example of an Indicator of Compromise (IOC)?

    Select an answer first
  3. 23foundation · easy

    What is a common hunting technique for detecting ransomware activity?

    Select an answer first
  4. 24application · medium

    After completing a threat hunt that found no malicious activity, a SOC analyst is preparing the final report. The hunt hypothesis was that a specific APT group might be using living-off-the-land binaries (LOLBins) for lateral movement. What should the analyst include in the report to ensure the hunt is valuable for future efforts?

    Select an answer first
  5. 25foundation · easy

    How are IOCs typically used in threat hunting?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.