Ec council CSa Practice Questions & Answers

Practise Ec council CSa with 201 questions and 1 full-length mock exams on Exam Clue. Free sample questions with answers below.

201 questions1 mock exams

Sample Ec council CSa Questions

Free sample questions with the correct answer highlighted.

  1. Q1. A user reports unusual large data exfiltration. What is your first action as L1 SOC Analyst?

    • A. Run a full antivirus scan on the endpoint
    • B. Run a full antivirus scan on the endpoint
    • C. Isolate the affected endpoint immediately
    • D. Ignore if no attachment
  2. Q2. You notice suspicious network traffic heading to a known C2 server (incident ID 1000). What is your first action as L1 SOC Analyst?

    • A. Check email headers for SPF/DKIM/DMARC and sender domain
    • B. Run a full antivirus/malware scan
    • C. Run a full antivirus/malware scan
    • D. Reset compromised user credentials
  3. Q3. As an L1 SOC Analyst, you receive an alert about unusual large volume data exfiltration to external server (incident ID 1001). What is your first action as L1 SOC Analyst?

    • A. Ignore the alert if no obvious signs of compromise
    • B. Check email headers for SPF/DKIM/DMARC and sender domain
    • C. Contain the incident by disabling network access
    • D. Isolate the affected endpoint immediately
  4. Q4. You notice suspicious email with malicious attachment (incident ID 1002). What is your first action as L1 SOC Analyst?

    • A. Block the suspicious IP address at firewall
    • B. Check email headers for SPF/DKIM/DMARC and sender domain
    • C. Contain the incident by disabling network access
    • D. Ignore the alert if no obvious signs of compromise
  5. Q5. You notice insider threat indicators from a privileged account. What is your first action as L1 SOC Analyst?

    • A. Ignore the alert if no obvious signs of compromise
    • B. Escalate the alert to L2 SOC Analyst
    • C. Check and update firewall and network rules
    • D. Quarantine the suspicious file or process
  6. Q6. As an L1 SOC Analyst, you receive an alert about account lockout due to repeated failed logins (incident ID 1004). What is your first action as L1 SOC Analyst?

    • A. Monitor for additional indicators of compromise
    • B. Run a full antivirus/malware scan
    • C. Quarantine the suspicious file or process
    • D. Ignore the alert if no obvious signs of compromise
  7. Q7. You notice brute force attack targeting VPN accounts. What is your first action as L1 SOC Analyst?

    • A. Ignore the alert if no obvious signs of compromise
    • B. Review and analyze authentication logs
    • C. Verify recent user permission changes
    • D. Contain the incident by disabling network access
  8. Q8. During monitoring you see SIEM alert for anomalous user behavior. What is your first action as L1 SOC Analyst?

    • A. Ignore the alert if no obvious signs of compromise
    • B. Check email headers for SPF/DKIM/DMARC and sender domain
    • C. Quarantine the suspicious file or process
    • D. Check email headers for SPF/DKIM/DMARC and sender domain