Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 4Objective 5

Endpoint and Network Data in SIEM SCE Practice Questions (Page 6)

Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
4concepts

Questions 26–30

  1. 26application · medium

    An analyst sees a SIEM alert that a workstation's antivirus detected a trojan. The same workstation also has a firewall log showing an outbound connection to a known malicious IP five minutes before the detection. Which action best leverages the combined data?

    Select an answer first
  2. 27application · medium

    A security analyst is investigating a possible port scan from an internal IP. Which network data source would provide the most direct evidence of the scan?

    Select an answer first
  3. 28application · medium

    A SOC analyst sees a firewall log showing outbound traffic from a finance workstation to an external IP on port 443, but no corresponding DNS query for that IP in the proxy logs. The analyst wants to determine whether the workstation actually executed a malicious process or whether the traffic was generated by a benign application. Which combination of data sources would best resolve this?

    Select an answer first
  4. 29expert · hard

    A SIEM is missing endpoint events from a subset of Windows workstations, but network logs are complete. The SOC suspects the missing events are due to the endpoints' local event logs being overwritten before forwarding. Which configuration change would most directly address this?

    Select an answer first
  5. 30foundation · easy

    A SOC analyst needs to identify which network data source provides summary information about IP conversations, including source and destination addresses, ports, and the amount of data transferred. Which type of network data should the analyst use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.