Question 8 of 10Pro Only

An endpoint detection tool alerts you that a suspicious executable was detected on a user's workstation. Walk through how you would investigate this potential malware infection using available logs and IOCs.

Sample answer preview

Investigating a potential malware infection requires a methodical approach that combines multiple data sources to understand the scope, severity, and origin of the threat. Here is how you would work through this investigation as an L1 SOC analyst.

endpoint detectionSIEMprocess treelateral movementcommand and controlVirusTotal

Unlock the full answer

Get the complete model answer, key points, common pitfalls, and access to 9+ more SOC Analyst interview questions.

Upgrade to Pro

Starting at $19/month • Cancel anytime