
EC-CouncilSOC Essentials
Domain 8Objective 2
Incident Classification and Prioritization SCE Practice Questions (Page 5)
Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 21–25
- 21
Which factor is most directly considered when prioritizing an incident that affects a system critical to the organization's core business operations?
Select an answer first - 22
A SOC analyst is triaging an alert that shows a user's workstation has been sending large amounts of data to an external cloud storage service during non-business hours. The user is a senior developer with access to source code repositories. The analyst has not yet confirmed whether the data transfer is legitimate. The company's data loss prevention (DLP) policy flags large outbound transfers as suspicious. What is the most appropriate triage decision?
Select an answer first - 23
An organization uses a risk matrix with four priority levels: low, medium, high, and critical. The matrix is based on likelihood and impact, with scores from 1 to 5. Incident A has a likelihood of 5 and an impact of 3. Incident B has a likelihood of 3 and an impact of 5. Which incident should be prioritized higher?
Select an answer first - 24
A SOC analyst is triaging an alert that indicates a user's workstation has been infected with ransomware, but the ransomware has not yet encrypted any files. The user is a temporary contractor who only has access to a shared project folder. The analyst has isolated the workstation. What is the most appropriate triage action?
Select an answer first - 25
A SOC uses a prioritization framework that assigns scores based on asset criticality (1-5), impact (1-5), and urgency (1-5), with a total score of 15. Incident A has an asset criticality of 5, impact of 4, and urgency of 2. Incident B has an asset criticality of 3, impact of 5, and urgency of 4. The SOC has resources to handle only one incident at a time. Which incident should be handled first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.