
EC-CouncilCertified SOC Analyst
Domain 5Objective 2
Threat Hunting CSA Practice Questions (Page 7)
Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.
49questions here
10free pages
10concepts
Questions 31–35
- 31
Why is documentation an important part of the threat hunting process?
Select an answer first - 32
A SOC analyst at a financial firm reads a threat intelligence report about a new banking trojan that uses PowerShell to download a second-stage payload from a legitimate cloud storage service. The analyst wants to proactively search the environment for signs of this activity before any alerts fire. Which approach best aligns with hypothesis-driven threat hunting?
Select an answer first - 33
A SOC team is hunting for an insider threat who is exfiltrating data via USB drives. The team has endpoint logs that record USB device insertion and file access events. However, the organization has a high volume of legitimate USB use. Which hunting approach would best identify the insider threat while minimizing false positives?
Select an answer first - 34
What is the primary purpose of a hypothesis in hypothesis-driven threat hunting?
Select an answer first - 35
A threat intelligence report provides a list of IOCs, including a domain, an IP, and a file hash. The SOC wants to hunt for these IOCs, but the log retention policy only keeps DNS logs for 7 days, proxy logs for 30 days, and EDR telemetry for 90 days. The hunt must cover the longest possible timeframe. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.