Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 2Objective 1

Understanding Cyber Threats and Attacks CSA Practice Questions (Page 6)

Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.

54questions here
11free pages
10concepts

Questions 26–30

  1. 26application · medium

    A SOC team receives a threat intelligence report indicating that a specific threat actor group is using a new phishing technique that bypasses email filters. The report includes indicators of compromise (IOCs) such as malicious domains and file hashes. What is the most effective way to use this intelligence to improve the organization's defenses?

    Select an answer first
  2. 27application · medium

    A SOC analyst is investigating a web application breach. The logs show that an attacker submitted a crafted input in a search field that caused the application to return an error message containing database table names and SQL syntax. The attacker then used this information to extract customer records. Which attack technique was used, and what is the most effective mitigation?

    Select an answer first
  3. 28application · medium

    A SOC analyst is reviewing firewall logs and notices that a user's workstation is communicating with an external IP address on port 445 (SMB). The workstation is not a file server, and the user has no business need to use SMB externally. The analyst also sees that the workstation has been making connections to multiple internal IPs on port 445. Which attack vector is most likely being exploited?

    Select an answer first
  4. 29foundation · easy

    Which of the following is an example of an attack vector?

    Select an answer first
  5. 30expert · hard

    A SOC team is reviewing threat intelligence and sees that a known threat actor group has been observed using a specific malware family that communicates with a command-and-control (C2) server using a custom protocol over port 443. The group typically uses spear-phishing with malicious attachments as their initial entry vector. The analyst's organization has a strong email filtering solution and up-to-date antivirus. Which additional defensive measure would be most effective in detecting this threat?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.