
EC-CouncilSOC Essentials
Domain 6Objective 3
Alerting and Triaging Alerts SCE Practice Questions (Page 3)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 11–15
- 11
A SIEM alert fires for 'multiple failed logins' from a single source IP against a file server. The source IP is a known internal workstation used by a marketing employee. The file server hosts non-confidential marketing assets. The employee has a history of forgetting passwords. What should the analyst do to enrich this alert before deciding on escalation?
Select an answer first - 12
A SOC analyst is triaging an alert that indicates a possible ransomware infection on a domain controller. The alert has high severity and high priority. The analyst has confirmed that multiple files are being encrypted with a known ransomware extension. According to escalation procedures, what should the analyst do?
Select an answer first - 13
A SOC analyst is triaging an alert for a potential data breach on a customer database. The alert is high severity but low priority because the database is in a test environment. The analyst finds that the database contains synthetic test data, not real customer data. However, the database is connected to a production network. What should the analyst do?
Select an answer first - 14
An analyst receives an alert about a user accessing a sensitive file share outside business hours. The analyst checks the user's behavior and finds that the user has a history of working late. The file share is not classified as critical. What is the most appropriate triage action?
Select an answer first - 15
A SOC analyst is triaging an alert about a potential malware infection on a standard user's workstation. The alert is low severity and low priority. After initial assessment, the analyst finds the file is a known false positive. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.