Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 6Objective 4

Dealing with False Positive Alerts SCE Practice Questions (Page 7)

Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts

Questions 31–35

  1. 31foundation · easy

    Why is it important to document false positive findings in a security operations center?

    Select an answer first
  2. 32application · medium

    A detection rule for 'Anomalous Outbound DNS Traffic' is generating a high volume of false positives because some endpoints use a legitimate dynamic DNS service. The rule currently triggers on any DNS query to a domain with a high entropy name. Which tuning change would most effectively reduce false positives while still detecting malicious DNS tunneling?

    Select an answer first
  3. 33expert · hard

    A SOC analyst is triaging a queue of alerts. One alert is a 'Medium' severity alert for 'Suspicious Scheduled Task' on a server that is known to have legitimate scheduled tasks. Another alert is 'Low' severity for 'Unusual Login Time' for a user who often works late. The analyst has limited time and must decide which alert to investigate first. The scheduled task alert is new, and the login time alert is recurring. Which alert should be investigated first?

    Select an answer first
  4. 34expert · hard

    A SOC team has been documenting false positives in a spreadsheet, but the detection engineering team is not using the documentation to improve rules. The false positive rate remains high, and analysts are frustrated. The team lead wants to improve the feedback loop. Which action is most likely to improve the situation?

    Select an answer first
  5. 35application · medium

    After investigating a recurring false positive alert, an analyst determines that the rule is triggering on a legitimate backup process that runs every night. The analyst wants to document the finding and provide feedback to improve the detection mechanism. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.