Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 8Objective 2

Incident Classification and Prioritization SCE Practice Questions (Page 6)

Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts

Questions 26–30

  1. 26foundation · easy

    An incident is classified as 'critical' and requires immediate action. What is the most appropriate escalation action?

    Select an answer first
  2. 27expert · hard

    A SOC has two incidents: Incident A is a ransomware infection on a file server that is used by the finance department. The server has been isolated, but the ransomware may have spread to other servers. Incident B is a phishing email that was opened by an executive, but no credentials were entered. The executive has access to merger and acquisition (M&A) data. The SOC has a limited incident response team and can only handle one incident at a time. Which incident should be prioritized?

    Select an answer first
  3. 28foundation · easy

    An incident is assigned a severity rating of 'High' based on a predefined scale. What is the primary purpose of using a severity rating framework?

    Select an answer first
  4. 29foundation · easy

    An organization discovers that a malicious program has encrypted files on a server and is demanding a ransom. Which incident category best describes this event?

    Select an answer first
  5. 30application · medium

    A SOC receives multiple alerts: (1) a user downloaded a trojanized PDF from a phishing email, (2) an unauthorized user attempted to log in to a VPN with a stolen credential but failed MFA, (3) a web server is receiving a high volume of UDP traffic from many sources, and (4) a database backup was found exposed on a public cloud storage bucket. Which incident should be categorized as a data breach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.