Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 6Objective 4

Dealing with False Positive Alerts SCE Practice Questions (Page 5)

Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts

Questions 21–25

  1. 21foundation · easy

    How can a high rate of false positives indirectly increase the risk of a successful cyberattack?

    Select an answer first
  2. 22application · medium

    A SOC analyst has confirmed that a recurring alert is a false positive caused by a legacy application that sends malformed network packets. The analyst wants to document the finding and provide feedback to improve the detection mechanism. What is the most appropriate way to document this?

    Select an answer first
  3. 23application · easy

    A SOC analyst receives an alert from an endpoint detection tool indicating that a user executed a PowerShell command that matches a known malicious script pattern. Upon investigation, the analyst determines that the user is a system administrator who ran a legitimate automation script that happens to contain similar syntax. The script is approved and documented. How should the analyst classify this alert?

    Select an answer first
  4. 24expert · hard

    A SOC analyst is triaging a queue of alerts. One alert is a 'High' severity alert for 'Data Exfiltration' from a file server, but the analyst knows that the file server is used for large data transfers by the marketing team. Another alert is 'Medium' severity for 'Malicious Command Execution' on a user workstation. The analyst has limited time and must decide which alert to investigate first. The file server alert has been recurring every day for a week, and the workstation alert is new. Which alert should be investigated first?

    Select an answer first
  5. 25application · medium

    A SOC team uses a SIEM rule that alerts when a user logs in outside of business hours. The rule generates many false positives because employees in different time zones and on-call staff regularly log in at night. The team wants to reduce false positives while still detecting unusual after-hours activity. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.