Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 4Objective 5

Endpoint and Network Data in SIEM SCE Practice Questions (Page 5)

Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
4concepts

Questions 21–25

  1. 21foundation · easy

    A SIEM correlates a network alert about a suspicious outbound connection with an endpoint alert showing a newly created process on the same host. What does this correlation enable the SOC to do?

    Select an answer first
  2. 22application · medium

    A SOC analyst needs to detect when a user attempts to run an unauthorized application on their workstation. Which endpoint data source would provide the most direct evidence?

    Select an answer first
  3. 23expert · hard

    A SOC needs to ingest full packet captures from a 10 Gbps network link into its SIEM for forensic analysis, but the storage budget only supports retaining 30 days of indexed logs. The team also needs real-time alerting on suspicious traffic patterns. Which approach best balances forensic completeness with cost and real-time detection?

    Select an answer first
  4. 24application · medium

    A SOC analyst notices that Windows event logs from domain controllers arrive in the SIEM with the raw Event ID and message text, but process creation events from the same hosts are missing the parent process ID. The analyst needs to correlate a suspected lateral movement chain that depends on parent-child process relationships. Which action best addresses the gap?

    Select an answer first
  5. 25expert · hard

    An organization has endpoint detection and response (EDR) and a SIEM. The EDR detects a suspicious PowerShell script on a host, but the SIEM does not show any corresponding network connection from that host. The analyst must decide whether to escalate. Which consideration is most important?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.