Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 6Objective 3

Alerting and Triaging Alerts SCE Practice Questions (Page 3)

Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
8concepts

Questions 11–15

  1. 11application · medium

    A SIEM alert fires for 'multiple failed logins' from a single source IP against a file server. The source IP is a known internal workstation used by a marketing employee. The file server hosts non-confidential marketing assets. The employee has a history of forgetting passwords. What should the analyst do to enrich this alert before deciding on escalation?

    Select an answer first
  2. 12application · medium

    A SOC analyst is triaging an alert that indicates a possible ransomware infection on a domain controller. The alert has high severity and high priority. The analyst has confirmed that multiple files are being encrypted with a known ransomware extension. According to escalation procedures, what should the analyst do?

    Select an answer first
  3. 13expert · hard

    A SOC analyst is triaging an alert for a potential data breach on a customer database. The alert is high severity but low priority because the database is in a test environment. The analyst finds that the database contains synthetic test data, not real customer data. However, the database is connected to a production network. What should the analyst do?

    Select an answer first
  4. 14application · medium

    An analyst receives an alert about a user accessing a sensitive file share outside business hours. The analyst checks the user's behavior and finds that the user has a history of working late. The file share is not classified as critical. What is the most appropriate triage action?

    Select an answer first
  5. 15application · medium

    A SOC analyst is triaging an alert about a potential malware infection on a standard user's workstation. The alert is low severity and low priority. After initial assessment, the analyst finds the file is a known false positive. What should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.