
EC-CouncilSOC Essentials
Domain 8Objective 2
Incident Classification and Prioritization SCE Practice Questions (Page 4)
Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 16–20
- 16
A SOC receives three alerts simultaneously: (1) a server is running a cryptocurrency miner, (2) a user's account has been locked out after multiple failed login attempts, and (3) a web application is returning errors due to a SQL injection attempt. The company's primary business is an e-commerce platform that processes credit card payments. Which incident should be categorized as having the highest potential business impact?
Select an answer first - 17
A SOC uses a 5x5 risk matrix with likelihood and impact ratings. An incident is assessed as having a likelihood of 4 (likely) and an impact of 5 (severe). According to the matrix, what is the appropriate prioritization level?
Select an answer first - 18
A SOC receives three alerts simultaneously. Alert 1: A phishing email was delivered to a user in the HR department, but the user did not click the link. Alert 2: A brute-force attack is targeting the VPN gateway, and several accounts have been locked out. Alert 3: A workstation in the R&D department is beaconing to a known command-and-control server. The SOC has limited staff and must prioritize. Which incident should be handled first?
Select an answer first - 19
A SOC analyst discovers that a database containing customer personal information has been accessed by an unauthorized external IP address. The database is used by the customer support team and contains sensitive data. The analyst has confirmed the breach but does not yet know the full extent of the data accessed. What is the most appropriate escalation action?
Select an answer first - 20
A SOC has two incidents to prioritize: Incident A is a phishing email that was opened by one user in the marketing department, but no credentials were entered. Incident B is a brute-force attack against the VPN gateway that has succeeded for one administrative account. The VPN is used by all remote employees. Which incident should be prioritized higher?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.