
EC-CouncilCertified SOC Analyst
Domain 5Objective 1
Threat Intelligence CSA Practice Questions (Page 8)
Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
10concepts
Questions 36–40
- 36
A SOC analyst is building a threat intelligence program and needs to prioritize sources. The analyst has access to a commercial feed with high confidence indicators, an open-source feed with a broad range of indicators, and internal telemetry from the company's own network. Which source should be considered the most authoritative for detecting threats specific to the company's environment?
Select an answer first - 37
A SOC analyst is tuning the SIEM to reduce false positives from a commercial threat intelligence feed. The feed includes a large volume of IP reputation data, but the analyst notices that many alerts fire for internal IP addresses that are being flagged by the feed. The analyst needs to ensure that only external IP addresses are checked against the feed while still maintaining detection for internal hosts communicating with known-bad external IPs. What is the most effective approach?
Select an answer first - 38
Which analytical method is used to identify relationships between seemingly unrelated indicators or events?
Select an answer first - 39
An analyst is reviewing a threat intelligence report that includes a new malware family. The report provides the malware's hash, C2 domains, and a description of its behavior. The analyst needs to create a detection rule. Which combination of intelligence is most effective for creating a robust detection rule?
Select an answer first - 40
A SOC analyst is investigating a potential insider threat. They need to understand the normal behavior of a specific user to identify anomalies. Which source of threat intelligence would be most valuable for this investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.