Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 5Objective 2

Threat Hunting CSA Practice Questions (Page 9)

Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.

49questions here
10free pages
10concepts

Questions 41–45

  1. 41foundation · easy

    During the validation phase of a threat hunt, what is the primary action an analyst performs?

    Select an answer first
  2. 42application · medium

    A SOC analyst is hunting for command-and-control (C2) communication. The analyst suspects that a compromised host is using DNS tunneling to exfiltrate data. Which combination of tools and data would be most effective for this hunt?

    Select an answer first
  3. 43application · medium

    A SOC team is hunting for ransomware that encrypts files and then deletes shadow copies. The team wants to detect this activity early, before widespread encryption occurs. Which hunting query would be most effective?

    Select an answer first
  4. 44expert · hard

    A SOC team is planning a hunt for a sophisticated adversary that uses legitimate cloud APIs for C2 and data exfiltration. The team has limited analyst time and must choose between two hypotheses: (1) the adversary uses a specific known cloud storage service for C2, or (2) the adversary uses multiple cloud services to blend in with normal traffic. Which approach is most effective given the constraint of limited analyst time?

    Select an answer first
  5. 45foundation · easy

    Which of the following is a valuable data source for threat hunting?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.