Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 5Objective 1

Threat Intelligence CSA Practice Questions (Page 6)

Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.

51questions here
11free pages
10concepts

Questions 26–30

  1. 26foundation · easy

    In the threat intelligence lifecycle, what is the primary purpose of the 'Planning and Direction' stage?

    Select an answer first
  2. 27foundation · easy

    Which stage of the threat intelligence lifecycle involves converting raw data into a form that can be understood by analysts?

    Select an answer first
  3. 28foundation · easy

    What is the primary benefit of integrating threat intelligence into a SIEM?

    Select an answer first
  4. 29application · medium

    An analyst is reviewing a suspicious email that bypassed the spam filter. The email contains a link to a domain that has not been seen before. The analyst wants to check if this domain is malicious using the SIEM. Which type of IoC would be most directly useful for querying the SIEM?

    Select an answer first
  5. 30expert · hard

    A SOC team is evaluating two threat intelligence feeds. Feed A provides a high volume of IoCs but has a high false positive rate. Feed B provides a lower volume but highly curated IoCs with low false positives. The team wants to reduce alert fatigue while maintaining good detection coverage. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.