
EC-CouncilCertified SOC Analyst
Domain 2Objective 1
Understanding Cyber Threats and Attacks CSA Practice Questions (Page 3)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
54questions here
11free pages
10concepts
Questions 11–15
- 11
A company is expanding its attack surface by allowing employees to use personal mobile devices to access corporate email and applications. The security team is concerned about new attack vectors. Which of the following is the most significant new attack vector introduced by this policy?
Select an answer first - 12
Which of the following best describes the primary motivation of a financially motivated cybercriminal group?
Select an answer first - 13
A SOC analyst notices that a legitimate user account has been downloading large amounts of sensitive data to a personal USB drive during off-hours. The user has no history of policy violations. Which type of insider threat does this represent, and what is the most appropriate immediate action?
Select an answer first - 14
A SOC team is investigating a series of incidents over the past year. They have observed: (1) spear-phishing emails sent to a few employees in the finance department, (2) a small number of malware detections on workstations that were quickly contained, (3) unusual outbound connections from a server that were blocked, and (4) a gradual increase in the volume of data being transferred to an external cloud storage service. The team has not been able to attribute these to a single cause, and the incidents have not caused significant disruption. Which hypothesis is most consistent with the observations?
Select an answer first - 15
A SOC analyst is investigating a data breach where sensitive customer records were exfiltrated. The investigation reveals that the data was accessed using a legitimate employee's credentials during business hours. The employee claims they did not download the data, but they did click on a link in a phishing email the previous day. Which type of insider threat is most likely responsible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.