
EC-CouncilSOC Essentials
Domain 4Objective 5
Endpoint and Network Data in SIEM SCE Practice Questions (Page 4)
Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
4concepts
Questions 16–20
- 16
A SOC team wants to detect data exfiltration attempts where an internal host sends large volumes of data to an external IP over HTTPS. The SIEM currently ingests firewall logs and DNS logs. Which additional network data source would most directly support this detection?
Select an answer first - 17
A SOC analyst is investigating a potential privilege escalation on a Linux server. Which endpoint data source would provide the most direct evidence of a user attempting to switch to the root account?
Select an answer first - 18
A SOC detects a workstation beaconing to an external IP every 60 seconds. Endpoint logs show a legitimate scheduled task running a maintenance script that makes an HTTP request to that IP. The IP is not on any threat intelligence list. What is the most appropriate next step?
Select an answer first - 19
An analyst is investigating a possible brute-force attack on a web server. The SIEM has web server access logs and authentication logs from the server. Which combination of data would provide the strongest evidence of a successful brute-force attack?
Select an answer first - 20
Which of the following is an example of endpoint data that a SIEM can ingest to detect malicious process activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.