
EC-CouncilCertified SOC Analyst
Domain 5Objective 2
Threat Hunting CSA Practice Questions (Page 5)
Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.
49questions here
10free pages
10concepts
Questions 21–25
- 21
A threat intelligence feed provides a list of malicious IP addresses and file hashes associated with a recent campaign. A SOC analyst wants to proactively search the environment for any signs of this campaign. Which approach is most appropriate?
Select an answer first - 22
Which of the following is an example of an Indicator of Compromise (IOC)?
Select an answer first - 23
What is a common hunting technique for detecting ransomware activity?
Select an answer first - 24
After completing a threat hunt that found no malicious activity, a SOC analyst is preparing the final report. The hunt hypothesis was that a specific APT group might be using living-off-the-land binaries (LOLBins) for lateral movement. What should the analyst include in the report to ensure the hunt is valuable for future efforts?
Select an answer first - 25
How are IOCs typically used in threat hunting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.