
EC-CouncilCertified SOC Analyst
Domain 2Objective 1
Understanding Cyber Threats and Attacks CSA Practice Questions (Page 9)
Part of the Cyber Threats and Attack Methodology domain, which makes up ~21% of our current practice bank.
54questions here
11free pages
10concepts
Questions 41–45
- 41
Which social engineering technique involves creating a fabricated scenario to trick a victim into divulging information?
Select an answer first - 42
A SOC analyst is investigating a web application that was defaced. The attacker exploited a vulnerability in the application's file upload feature to upload a malicious script. The script then modified the website's homepage. The analyst also notices that the attacker used the same vulnerability to upload a web shell, which could allow further access. Which attack vector was used, and what is the most important remediation step?
Select an answer first - 43
A SOC analyst discovers that a file on a user's workstation is encrypting files and displaying a ransom note demanding payment in cryptocurrency. The analyst also notices that the malware attempted to spread to network shares. Which type of malware is this, and what is the immediate containment step?
Select an answer first - 44
During an incident investigation, a SOC analyst maps the attacker's actions to the cyber kill chain. The attacker first scanned the network for open ports, then exploited a vulnerability in a web server, installed a backdoor, and is now exfiltrating data. Which stage of the kill chain is the attacker currently in?
Select an answer first - 45
What is the primary human vulnerability that social engineering exploits?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.