Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 5Objective 1

Events, Incidents, and Logs SCE Practice Questions (Page 8)

Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
5concepts

Questions 36–39

  1. 36foundation · easy

    Which of the following scenarios best illustrates an incident rather than a single event?

    Select an answer first
  2. 37application · medium

    A junior analyst asks a senior analyst: 'We have a log entry showing an administrator successfully logging in at 2:00 AM, which is unusual. Is this an incident?' Which response is most accurate?

    Select an answer first
  3. 38expert · hard

    A company is consolidating logs from multiple sources into a SIEM. Some sources send syslog, others send JSON, and a few send CSV. The SIEM has parsers for all three formats. The team wants to ensure that all logs are searchable and correlated. What is the most important step in the consolidation process?

    Select an answer first
  4. 39application · medium

    A SOC analyst sees a single log entry indicating that a user accessed a sensitive file at 2:00 PM. Later, the analyst discovers that the user's account was compromised and the file access was part of a larger data exfiltration. How should the analyst classify the single file access?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to SCE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.