
EC-CouncilSOC Essentials
Domain 5Objective 1
Events, Incidents, and Logs SCE Practice Questions (Page 2)
Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 6–10
- 6
An analyst notices a spike in failed logins for a service account, followed by a successful login from a new IP address. The analyst creates a ticket. Which step should the analyst take next to determine if this is an incident?
Select an answer first - 7
A SOC analyst is investigating a potential brute-force attack on a web application. Which log source would provide the most direct evidence of the attack?
Select an answer first - 8
During an investigation, an analyst finds that a user's account was used to log in from two different countries within 5 minutes. The analyst checks VPN logs and finds that the user has a valid VPN session from the first country. What is the most likely conclusion?
Select an answer first - 9
A SOC team is integrating a new cloud-based application that sends logs in JSON format. The existing on-premises SIEM expects syslog. The team wants to minimize data loss and preserve the structured data. What is the best approach?
Select an answer first - 10
A SOC analyst is reviewing logs and finds a single failed login attempt from a known malicious IP address. No other related activity is found. According to standard definitions, how should this be classified?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.