Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 5Objective 1

Events, Incidents, and Logs SCE Practice Questions (Page 3)

Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
5concepts

Questions 11–15

  1. 11application · medium

    A company wants to improve detection of insider threats involving unauthorized access to sensitive files. Which log sources are most critical to enable this detection?

    Select an answer first
  2. 12expert · hard

    During an incident, an analyst notices that the attacker deleted some logs on the compromised server. Which action should the analyst take to preserve evidence?

    Select an answer first
  3. 13application · medium

    During a suspected data breach, a SOC analyst needs to determine the timeline of an attacker's actions. Which log sources should the analyst prioritize to reconstruct the attack sequence?

    Select an answer first
  4. 14application · medium

    A company's SIEM is not receiving logs from a newly deployed web application firewall (WAF). The WAF supports syslog and JSON output. The SIEM's default parser expects syslog with a specific facility. Which action is most appropriate to integrate the WAF logs?

    Select an answer first
  5. 15foundation · easy

    Which of the following is a common source of security logs?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.