Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 8Objective 2

Incident Classification and Prioritization SCE Practice Questions (Page 3)

Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts

Questions 11–15

  1. 11application · medium

    A SOC analyst is handling a suspected data breach involving customer credit card information. The incident is classified as high severity and high impact. According to the escalation procedure, what should the analyst do?

    Select an answer first
  2. 12foundation · easy

    Which set of criteria is most commonly used to classify a security incident?

    Select an answer first
  3. 13expert · hard

    A SOC analyst is handling an incident where a disgruntled employee is attempting to access a confidential HR database using another employee's credentials. The analyst has confirmed the unauthorized access attempts but has not yet determined if any data was viewed. The company's escalation policy states that incidents involving potential data breaches must be escalated within 30 minutes. The analyst has been working on the incident for 20 minutes and has not yet confirmed data access. What should the analyst do?

    Select an answer first
  4. 14foundation · easy

    An incident is classified as 'high severity' because it affects a critical business application and could cause significant financial loss. Which classification criteria are being applied?

    Select an answer first
  5. 15expert · hard

    A SOC analyst is classifying an incident where an employee's laptop was stolen from a coffee shop. The laptop contains encrypted company data and the employee's credentials were stored in a password manager on the laptop. The company's security policy requires that all laptops be encrypted, but the analyst discovers that the laptop's hard drive was not encrypted. What is the most appropriate classification?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.