
EC-CouncilSOC Essentials
Domain 5Objective 1
Events, Incidents, and Logs SCE Practice Questions (Page 1)
Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 1–5
- 1
Which of the following is a common log format used for network device logs?
Select an answer first - 2
A security team needs to ingest logs from a mix of network devices that support syslog and cloud applications that output JSON. The SIEM can parse both formats. What is the primary consideration when configuring the ingestion pipeline?
Select an answer first - 3
Which of the following is a structured log format that is commonly used for application logs?
Select an answer first - 4
During an incident investigation, an analyst needs to prove that an attacker accessed a specific file on a server. The server's file access logging is not enabled. Which alternative log source could provide evidence of the file access?
Select an answer first - 5
A SOC is investigating a ransomware attack. They have logs from the firewall, endpoint, and backup system. The firewall logs show outbound connections to a known C2 server. The endpoint logs show the ransomware executable running. The backup logs show that backups were deleted. Which statement best describes the role of these logs in the investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.