
EC-CouncilSOC Essentials
Domain 6Objective 3
Alerting and Triaging Alerts SCE Practice Questions (Page 8)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 36–40
- 36
A SOC team is required to provide a monthly report on alert triage effectiveness. The team wants to show how many alerts were true positives, false positives, and how many were escalated. What is the best way to ensure accurate reporting?
Select an answer first - 37
What should be recorded when documenting a triage action for an alert?
Select an answer first - 38
After escalating an alert to incident response, the analyst receives feedback that the escalation was unnecessary because the activity was benign. What should the analyst do to improve future triage?
Select an answer first - 39
Which statement best describes how alerts are generated in a typical SIEM environment?
Select an answer first - 40
A SOC analyst is reviewing an alert that was generated by a rule designed to detect credential dumping. The analyst finds that the rule did not fire for a known credential dumping attack that occurred on the same network. How should the analyst classify the missed detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.