
EC-CouncilSOC Essentials
Domain 6Objective 3
Alerting and Triaging Alerts SCE Practice Questions (Page 6)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 26–30
- 26
A SOC analyst receives an alert for a potential privilege escalation on a critical database server. The alert is medium severity but high priority because the asset is critical. The analyst has limited information in the alert. What is the next step in the triage process?
Select an answer first - 27
A SOC analyst receives an alert for a suspicious PowerShell command on a domain controller. The alert severity is 'high' because the rule matches a known attacker technique, but the asset criticality of the domain controller is also 'high'. The analyst checks the user's behavior and finds that the user routinely runs PowerShell scripts for administrative tasks. What should the analyst do first?
Select an answer first - 28
An alert fires, but after investigation, the analyst determines that the activity was benign and did not represent a real threat. How should this alert be categorized?
Select an answer first - 29
A security team wants to detect attempts to exploit a known vulnerability in a web application. They have a network IDS and a SIEM. Which alert generation method would be most effective?
Select an answer first - 30
A SOC team uses a triage queue. Alert A is a medium-severity alert on a domain controller (critical asset). Alert B is a high-severity alert on a non-critical file server. Both are unvalidated. Which alert should the analyst triage first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.