
EC-CouncilSOC Essentials
Domain 6Objective 4
Dealing with False Positive Alerts SCE Practice Questions (Page 1)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 1–5
- 1
A SOC team receives 500 alerts per hour. Most are low-severity false positives from a legacy IDS. A critical alert about a potential data exfiltration is buried in the queue. The team has limited staff and cannot manually review every alert. Which approach best improves the team's ability to identify the critical alert quickly?
Select an answer first - 2
A SOC team has a limited number of analysts and a high volume of alerts. The team uses a SIEM with a risk-scoring system, but the scores are not calibrated, and many low-risk alerts are actually true positives while some high-risk alerts are false positives. The team wants to improve triage efficiency without missing genuine threats. Which approach is most effective?
Select an answer first - 3
A SOC team is overwhelmed by a high volume of false positive alerts. As a result, analysts have started ignoring alerts from a particular detection source. A genuine intrusion attempt generates an alert from that same source, but no one reviews it in time, and the attacker successfully exfiltrates data. Which concept best describes this situation?
Select an answer first - 4
A SOC team notices that a detection rule for 'suspicious PowerShell activity' generates many alerts for the IT team's legitimate automation scripts. What is the best tuning approach to reduce these false positives?
Select an answer first - 5
A security team uses a SIEM rule that alerts when a user logs in from a new geographic location. The rule generates many false positives because employees frequently travel and use VPN endpoints that appear in different locations. The team wants to reduce false positives while still detecting unusual travel patterns. Which configuration change is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.