
EC-CouncilSOC Essentials
Domain 6Objective 4
Dealing with False Positive Alerts SCE Practice Questions (Page 8)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 36–40
- 36
A detection rule for 'Anomalous Network Traffic' is generating false positives because a new network monitoring tool is sending large amounts of data that the rule interprets as suspicious. The rule was tuned for the previous network baseline. The analyst must reduce false positives without losing detection of real anomalies. Which action is most appropriate?
Select an answer first - 37
A SOC team is experiencing a high rate of false positives from a specific detection rule. The rule is designed to detect command-and-control (C2) beaconing by flagging regular outbound connections to a single external IP. Analysts are spending significant time investigating these alerts, and as a result, a genuine C2 alert from a different rule was missed. The team has limited resources and cannot manually review every alert. Which approach best balances the need to reduce false positives while maintaining detection of C2 activity?
Select an answer first - 38
A SOC analyst is triaging a queue of alerts. One alert is a 'Critical' severity alert for 'Lateral Movement' from a domain controller, but the analyst knows that the domain controller was recently patched and rebooted. Another alert is 'Medium' severity for 'Unusual Outbound Connection' from a user workstation. The analyst has limited time. Which alert should be investigated first?
Select an answer first - 39
A detection rule for 'Excessive Failed Logons' is generating false positives because a legacy application uses a service account that periodically locks out. The rule currently triggers on 10 failed logons within 5 minutes. The analyst wants to reduce false positives without missing a brute-force attack. Which tuning change is most appropriate?
Select an answer first - 40
During alert triage, which finding most strongly suggests that an alert is a false positive?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SCE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.