
EC-CouncilSOC Essentials
Domain 6Objective 3
Alerting and Triaging Alerts SCE Practice Questions (Page 9)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 41–42
- 41
A SOC analyst triages an alert and determines it is a false positive. The analyst closes the alert but does not record the reason or the investigation steps. Later, the same alert pattern repeats, and another analyst spends time investigating it again. What is the primary problem with the analyst's action?
Select an answer first - 42
An alert fires for 'unusual outbound traffic' from a server that hosts a public API. The alert is based on a baseline of normal traffic. The analyst checks threat intelligence and finds the destination IP is a known cloud provider. The server's logs show the traffic is from an API client that recently increased its usage. The analyst also notes that the server is not critical. What is the most appropriate classification?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SCE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.