Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 5Objective 1

Threat Intelligence CSA Practice Questions (Page 1)

Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.

51questions here
11free pages
10concepts

Questions 1–5

  1. 1application · medium

    A SOC manager needs to brief the executive board on the likelihood of a specific threat actor targeting the company's industry. The briefing must include the actor's motivations, typical targets, and the potential business impact. Which type of threat intelligence should the SOC manager primarily use for this briefing?

    Select an answer first
  2. 2foundation · easy

    How does a threat intelligence feed enhance detection in a SIEM?

    Select an answer first
  3. 3application · medium

    A SOC team wants to integrate threat intelligence feeds into their IDS/IPS to block traffic to known malicious IPs. However, they are concerned about the performance impact of checking every packet against a large feed. What is the most effective way to integrate the feed while minimizing performance impact?

    Select an answer first
  4. 4application · medium

    An analyst is reviewing a threat intelligence report that lists a set of IP addresses associated with a command-and-control (C2) infrastructure. The analyst wants to determine if any internal hosts have communicated with these IPs in the past 30 days. Which approach is most efficient for this analysis?

    Select an answer first
  5. 5application · medium

    A SOC analyst is explaining the value of threat intelligence to a new team member. The analyst wants to emphasize how threat intelligence supports proactive threat detection. Which statement best describes this role?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.