Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 6Objective 3

Alerting and Triaging Alerts SCE Practice Questions (Page 2)

Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
8concepts

Questions 6–10

  1. 6application · medium

    A SIEM rule detects a single outbound connection to a known command-and-control (C2) IP address from a workstation. The analyst investigates and finds that the workstation's DNS cache contains the C2 domain, and a process on the workstation is actively communicating with the IP. No other hosts are affected. How should the analyst classify this alert?

    Select an answer first
  2. 7application · medium

    A SOC analyst is triaging an alert about a potential data exfiltration from a finance server. The analyst has confirmed that the activity is malicious and that the server contains sensitive customer data. The incident is ongoing. According to the triage process, what should the analyst do next?

    Select an answer first
  3. 8application · medium

    A SOC analyst reviews an alert generated by an IDS rule that flags any outbound connection to a known malicious IP. The analyst investigates and finds that the connection was made by a legitimate internal service that uses a public IP that was previously flagged but is now owned by a benign cloud provider. How should this alert be classified?

    Select an answer first
  4. 9application · medium

    A SOC analyst receives an alert for a single failed login to a domain admin account from a known internal IP. The alert is rated 'high severity' by the SIEM because the account is privileged. The analyst checks the user's recent activity and finds the user successfully logged in 30 seconds later from the same workstation. The failed attempt appears to be a typo in the password. What should the analyst do first?

    Select an answer first
  5. 10application · medium

    A SIEM rule generates many alerts for 'admin login outside business hours' from a specific user. Investigation shows the user is a system administrator who regularly performs maintenance at night. The alerts are all false positives. What is the best way to reduce these false positives while maintaining detection for other users?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.