
EC-CouncilCertified SOC Analyst
Domain 5Objective 2
Threat Hunting CSA Practice Questions (Page 8)
Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.
49questions here
10free pages
10concepts
Questions 36–40
- 36
A SOC manager wants to justify the value of threat hunting to leadership. Which statement best describes how threat hunting differs from traditional security monitoring?
Select an answer first - 37
During a threat hunt, an analyst observes a sequence of events on a single workstation: a PowerShell process spawning from an Office application, followed by a scheduled task creation, and then an outbound connection to an unusual IP. The analyst has not yet identified any known malware signatures. How should the analyst interpret this finding?
Select an answer first - 38
A SOC is hunting for a suspected APT that is known to use DLL sideloading and scheduled tasks for persistence. The team has access to Sysmon, PowerShell logs, and EDR telemetry, but limited time. The hunt must cover both execution and persistence. Which approach best balances coverage and efficiency?
Select an answer first - 39
A SOC team is planning a hunt for possible data exfiltration by an insider threat. The hunt must cover both network-level and endpoint-level activity. Which combination of data sources would provide the most comprehensive visibility for this hunt?
Select an answer first - 40
Which of the following is the best source for developing a hypothesis for a threat hunt?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.