Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 5Objective 1

Threat Intelligence CSA Practice Questions (Page 2)

Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.

51questions here
11free pages
10concepts

Questions 6–10

  1. 6application · medium

    A SOC analyst is explaining to a new team member why threat intelligence is important for proactive threat detection. The analyst wants to emphasize how intelligence helps the team anticipate attacks rather than just react to them. Which statement best illustrates this proactive benefit?

    Select an answer first
  2. 7foundation · easy

    Why are file hashes considered a reliable type of IoC for detecting known malware?

    Select an answer first
  3. 8expert · hard

    A SOC analyst has discovered a new zero-day vulnerability being exploited in the wild. The analyst wants to share this information with other organizations quickly, but is concerned about the vulnerability being exploited further before patches are available. What is the most responsible way to share this intelligence?

    Select an answer first
  4. 9application · medium

    A SOC analyst is creating a detection rule for a new malware campaign. The analyst has a malicious file hash, a C2 domain, and a specific user-agent string used by the malware. Which indicator is the most reliable for detecting the malware across different environments?

    Select an answer first
  5. 10foundation · easy

    An organization's SOC wants to incorporate threat intelligence that reflects its own network environment and past incidents. Which type of source would best provide this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.