
EC-CouncilCertified SOC Analyst
Domain 2Objective 1
Understanding Cyber Threats and Attacks CSA Practice Questions (Page 2)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
54questions here
11free pages
10concepts
Questions 6–10
- 6
A SOC analyst is investigating an incident where a contractor accidentally emailed a spreadsheet containing customer PII to the wrong recipient. The contractor had been granted temporary access to the data for a project. Which type of insider threat does this represent, and what is the most important lesson for the organization?
Select an answer first - 7
A SOC analyst is reviewing a phishing campaign targeting the company. The emails are highly personalized, using the target's name, job title, and recent social media activity. The emails contain a link to a fake login page that mimics the company's single sign-on (SSO) portal. The analyst notices that the emails are only sent to a small group of high-level executives. Which type of social engineering attack is this, and what is the most effective defense?
Select an answer first - 8
What is the primary role of threat intelligence in a SOC?
Select an answer first - 9
What is the primary impact of a Cross-Site Scripting (XSS) attack?
Select an answer first - 10
A SOC analyst is investigating a report of slow network performance and unusual SSL certificates on an internal web application. The analyst suspects a man-in-the-middle (MITM) attack. Which evidence would most strongly confirm this suspicion?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.