
EC-CouncilSOC Essentials
Domain 6Objective 4
Dealing with False Positive Alerts SCE Practice Questions (Page 6)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 26–30
- 26
A SOC team uses a network detection rule that alerts when a host communicates with an IP address on a threat intelligence blocklist. The rule generates many false positives because a legitimate SaaS application used by the company shares an IP range with a known malicious actor. The team wants to reduce false positives without losing visibility into malicious communications. Which action is most appropriate?
Select an answer first - 27
A SOC team is tuning a detection rule that alerts on the use of a specific hacking tool. The rule currently generates a high number of false positives because a legitimate penetration testing team uses the same tool during scheduled assessments. The team wants to reduce false positives while maintaining detection of unauthorized use of the tool. The penetration testing schedule is known in advance. Which approach is most appropriate?
Select an answer first - 28
A SOC analyst notices that a specific EDR rule triggers dozens of times per day on a developer workstation. The alert fires when a process reads the Windows registry key that stores the last user's logon time. Developers routinely run a build tool that queries this key. The rule was originally created to detect credential-access techniques. The analyst wants to reduce noise without losing visibility into genuine credential-access attempts. Which action is most appropriate?
Select an answer first - 29
An organization's intrusion detection system (IDS) is generating many alerts for a specific signature that matches a legitimate internal application's traffic. What is the most likely cause of these false positives?
Select an answer first - 30
A SOC team is experiencing a high rate of false positives, and analysts are beginning to ignore alerts. The team lead is concerned that a true positive will be missed. The team has limited resources and cannot increase staffing. Which strategy is most effective for mitigating the risk of missing a true positive?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.