Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 4Objective 5

Endpoint and Network Data in SIEM SCE Practice Questions (Page 2)

Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
4concepts

Questions 6–10

  1. 6application · medium

    An analyst is investigating a malware infection that communicates over HTTP. Which network data source would provide the most useful information about the malware's command-and-control activity?

    Select an answer first
  2. 7application · medium

    A SOC wants to detect when a user installs unauthorized software on their workstation. Which endpoint data source would provide the most direct evidence?

    Select an answer first
  3. 8expert · hard

    An organization has a SIEM that ingests endpoint logs (Windows Event Logs, Sysmon) and network logs (firewall, proxy). A user's workstation shows a PowerShell process that made an outbound connection to a known malicious IP. The firewall log confirms the connection, but the proxy log shows no request for that IP. The analyst needs to determine if the connection was blocked or allowed. Which data source should the analyst prioritize?

    Select an answer first
  4. 9expert · hard

    A SOC is investigating a data breach. The SIEM shows a large outbound transfer from a database server to an external IP, but the endpoint logs for that server are incomplete because the server was recently rebuilt. Which network data source would be most valuable for determining what data was exfiltrated?

    Select an answer first
  5. 10expert · hard

    A SOC team is investigating a potential insider threat. The SIEM shows that an employee's workstation accessed a sensitive database and then made a large outbound transfer to a personal cloud storage service. Which combination of data sources provides the most complete evidence for the investigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.