Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 1

Understanding Cyber Threats and Attacks CSA Practice Questions (Page 11)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

54questions here
11free pages
10concepts

Questions 51–54

  1. 51application · medium

    A SOC analyst is investigating a phishing incident where an employee received an email that appeared to be from the company's IT department. The email urged the employee to 'verify' their account by clicking a link and entering their password. The employee did so, and the credentials were later used to access the corporate VPN. Which social engineering technique is most directly demonstrated in this scenario?

    Select an answer first
  2. 52foundation · easy

    Which stage of the APT lifecycle involves establishing a foothold in the target network?

    Select an answer first
  3. 53expert · hard

    A SOC analyst is reviewing threat intelligence and notices that a known threat actor group has been observed using a specific malware family that communicates with a command-and-control (C2) server using a custom protocol over port 443. The group typically uses spear-phishing with malicious attachments as their initial entry vector. The analyst's organization has a strong email filtering solution and up-to-date antivirus. Which additional defensive measure would be most effective in detecting this threat?

    Select an answer first
  4. 54foundation · easy

    What is a unique risk posed by insider threats compared to external attackers?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.