
EC-CouncilSOC Essentials
Domain 6Objective 2
Correlation Rules, Dashboards, and Reports SCE Practice Questions (Page 4)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
10concepts
Questions 16–20
- 16
A SOC team has deployed a correlation rule that triggers an alert when a user account has 5 failed logins within 10 minutes. The rule is generating an overwhelming number of alerts, most of which are due to users mistyping their passwords. The team wants to reduce false positives while still detecting actual brute-force attacks. Which tuning approach is most appropriate?
Select an answer first - 17
A SOC team wants to automatically send a daily summary of high-severity alerts to the on-call incident responder at 9:00 AM. The report should include the alert count and a list of the top 5 alerts. Which configuration is correct?
Select an answer first - 18
In a correlation rule, what does the 'time window' component specify?
Select an answer first - 19
A correlation rule is designed to detect port scanning by triggering when a single source IP connects to more than 20 distinct destination ports on the same host within 10 minutes. The rule is generating many false positives because a legitimate monitoring tool scans ports every 5 minutes. The team wants to keep the rule but reduce false positives. Which change is most effective?
Select an answer first - 20
A SOC team wants to detect a multi-stage attack where an attacker first performs a port scan, then exploits a vulnerability, and finally establishes a command-and-control (C2) connection. The team has logs from network sensors, vulnerability scanners, and endpoint agents. What is the best way to detect this attack pattern?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.