
EC-CouncilCertified SOC Analyst
Domain 2Objective 1
Understanding Cyber Threats and Attacks CSA Practice Questions (Page 8)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
54questions here
11free pages
10concepts
Questions 36–40
- 36
A SOC analyst is investigating a network anomaly where a server is receiving a large volume of UDP packets from many different source IPs. The packets are small, and the destination port is 53 (DNS). The server is not a DNS server, but it is responding to these packets with larger DNS responses. The analyst suspects a DNS amplification attack. Which defensive measure would be most effective in mitigating this attack?
Select an answer first - 37
What is the primary goal of a Distributed Denial of Service (DDoS) attack?
Select an answer first - 38
A SOC team has been investigating a series of small, seemingly unrelated security incidents over the past six months. The incidents include spear-phishing emails to specific employees, occasional malware detections on a few workstations, and unusual outbound connections from a server that were quickly blocked. The team has not been able to attribute these to a single cause. Which characteristic of an advanced persistent threat (APT) is most clearly demonstrated by this pattern?
Select an answer first - 39
Which statement best reflects the evolving nature of the current cyber threat landscape?
Select an answer first - 40
A SOC team is investigating a breach that has been ongoing for over a year. The attacker used a zero-day exploit to gain initial access, then moved laterally using legitimate administrative tools. The attacker has been exfiltrating data in small amounts to avoid detection. The team has identified the attacker's command-and-control (C2) infrastructure. Which of the following actions would be the most effective to disrupt the attack while minimizing the risk of alerting the attacker?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.