
EC-CouncilSOC Essentials
Domain 6Objective 4
Dealing with False Positive Alerts SCE Practice Questions (Page 3)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 11–15
- 11
A SOC team has a documented process for handling false positives. An analyst identifies a new false positive caused by a recently deployed application. The analyst documents the finding and submits a tuning recommendation to the detection engineering team. However, the detection engineering team is backlogged and cannot implement the change for several weeks. In the meantime, the false positive continues to generate alerts. What is the most appropriate action for the analyst to take?
Select an answer first - 12
A SOC analyst notices that a detection rule for 'Malicious File Download' is generating many false positives after a recent software update. The rule uses a signature that matches a specific file hash. The software update changed the hash of a legitimate application that is widely used in the organization. What is the most likely cause of the false positives?
Select an answer first - 13
A company recently deployed a new EDR solution. The SOC team notices that the EDR generates many false positives for a legitimate software update process that runs nightly. The update process downloads files from a vendor CDN and executes them. The EDR rule flags the execution of files from an untrusted domain. The team wants to reduce false positives without weakening detection of actual malware downloads. Which approach is most appropriate?
Select an answer first - 14
A SOC team has been receiving hundreds of false positive alerts per day from a misconfigured IDS rule. Analysts have started to ignore the alerts because they are almost always benign. One day, a real intrusion triggers the same rule, but the alert is not investigated until the next shift. What is the most significant operational impact of this situation?
Select an answer first - 15
Which technique is most effective for reducing false positives while preserving detection of genuine threats?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.