Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 5Objective 2

Threat Hunting CSA Practice Questions (Page 6)

Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.

49questions here
10free pages
10concepts

Questions 26–30

  1. 26application · medium

    A SOC analyst is about to start a threat hunt for lateral movement using pass-the-hash techniques. The analyst has a hypothesis and has identified relevant data sources. What should the analyst do immediately after collecting the data?

    Select an answer first
  2. 27expert · hard

    A SOC is hunting for an insider threat who may be using legitimate administrative tools to perform unauthorized actions. The hunt must avoid generating false positives that would disrupt legitimate admin work. Which hunting approach best balances detection and false-positive reduction?

    Select an answer first
  3. 28application · medium

    A SOC manager wants to implement a proactive threat hunting program. The team currently relies on alerts from the SIEM and EDR. Which of the following best describes the key difference between threat hunting and traditional security monitoring that the manager should consider?

    Select an answer first
  4. 29foundation · easy

    What should be included in a threat hunting report to effectively communicate results to management?

    Select an answer first
  5. 30foundation · easy

    What is the correct sequence of steps in the threat hunting process?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.