Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 6Objective 4

Dealing with False Positive Alerts SCE Practice Questions (Page 2)

Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts

Questions 6–10

  1. 6application · medium

    A SOC analyst discovers that a detection rule for a specific malware family is generating false positives because a legitimate internal tool uses the same file hash as a sample in the threat intelligence feed. The analyst has confirmed the tool is benign and widely used across the organization. What is the most appropriate action to prevent future false positives?

    Select an answer first
  2. 7application · medium

    A security analyst notices that a detection rule for 'Suspicious PowerShell Execution' fires hundreds of times per day. Investigation shows the alerts are triggered by a legitimate administrative script that runs every 15 minutes on a small set of servers. The rule is a built-in signature that cannot be modified directly. What should the analyst do first to reduce the noise while preserving detection for other hosts?

    Select an answer first
  3. 8expert · hard

    A detection rule for 'Suspicious PowerShell' is generating false positives because a legitimate automation script uses PowerShell to perform administrative tasks. The rule currently alerts on any PowerShell execution that includes the 'Invoke-Expression' cmdlet. The script is used by the IT team on a specific set of servers. The analyst must reduce false positives without losing detection of malicious PowerShell on other hosts. Which tuning approach is most effective?

    Select an answer first
  4. 9foundation · easy

    What is the first step in efficiently triaging a security alert to determine if it is a false positive?

    Select an answer first
  5. 10application · medium

    A SOC analyst identifies a recurring false positive caused by a misconfigured detection rule. The rule triggers on a legitimate internal application that uses the same network signature as a known malware family. The analyst has confirmed the application is benign and the rule is too broad. What is the most appropriate next step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.