Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 1

Understanding Cyber Threats and Attacks CSA Practice Questions (Page 1)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

54questions here
11free pages
10concepts

Questions 1–5

  1. 1expert · hard

    A SOC analyst is analyzing a malware sample that was found on a compromised host. The malware is a file that, when executed, drops a payload that creates a backdoor and also spreads to other hosts by exploiting a network vulnerability. The malware does not require user interaction to spread. Which type of malware is this, and what is the most important containment action?

    Select an answer first
  2. 2foundation · easy

    Which of the following best describes an insider threat?

    Select an answer first
  3. 3application · medium

    A SOC analyst is reviewing recent alerts and notices a pattern: a series of phishing emails targeting employees in the finance department, with the goal of convincing them to transfer funds to a specific bank account. The emails are personalized with the employees' names and job titles. Which threat actor profile is most consistent with this activity?

    Select an answer first
  4. 4expert · hard

    A SOC analyst is reviewing web application logs and sees a series of requests to a search endpoint that include the parameter 'q' with values like "<script>alert(1)</script>". The requests are coming from a single IP address, and the responses include the same script in the page source. The analyst also notices that the application is reflecting the 'q' parameter in the response without sanitization. Which type of web application attack is being attempted, and what is the most likely impact if successful?

    Select an answer first
  5. 5application · medium

    A SOC team is reviewing threat intelligence feeds and notices that a specific malware family is being distributed via malicious email attachments that use a recently discovered vulnerability in a common PDF reader. The team wants to proactively defend against this threat. Which action is most directly informed by this threat intelligence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.