
EC-CouncilCertified SOC Analyst
Domain 5Objective 1
Threat Intelligence CSA Practice Questions (Page 5)
Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
10concepts
Questions 21–25
- 21
Which security tool is most commonly integrated with threat intelligence to automatically block traffic from known malicious IP addresses?
Select an answer first - 22
A SOC team wants to share indicators of compromise with partner organizations in a standardized, machine-readable format. They also want to automate the exchange of these indicators with a trusted community platform. Which combination of standards and protocols should they implement?
Select an answer first - 23
What is the primary purpose of threat intelligence in a SOC environment?
Select an answer first - 24
A SOC analyst is tuning the SIEM to reduce false positives on a new malware campaign. The team has a commercial threat feed that provides SHA256 hashes of known malicious files, but the SIEM currently only ingests Windows Event Logs. Which action would best leverage the feed to improve detection?
Select an answer first - 25
What is the primary benefit of using threat intelligence to identify emerging threats?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.