
EC-CouncilSOC Essentials
Domain 8Objective 2
Incident Classification and Prioritization SCE Practice Questions (Page 8)
Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 36–40
- 36
A SOC receives an alert about a DDoS attack targeting the company's public web server. The attack is causing intermittent availability issues. The web server is not business-critical, but it is customer-facing. How should this incident be classified?
Select an answer first - 37
A SOC uses a risk matrix with two dimensions: likelihood (low, medium, high) and impact (low, medium, high). The SOC has two incidents: Incident A is a malware infection on a single non-critical workstation, with a likelihood of further spread assessed as medium and impact of low. Incident B is a phishing email that was opened by a user in finance, but no credentials were entered; likelihood of credential compromise is low, but impact is high. The SOC has limited resources and can only fully investigate one incident at a time. Which incident should be investigated first?
Select an answer first - 38
During triage, a SOC analyst receives an alert about a user account that has been used to log in from two different countries within a short time period. The user is a remote employee who frequently travels. What should the analyst do first?
Select an answer first - 39
Which tool is commonly used to rank incidents by combining the likelihood of occurrence with the severity of impact?
Select an answer first - 40
A SOC analyst is classifying an incident where a web server is experiencing a distributed denial of service (DDoS) attack, causing the company's public website to be intermittently unavailable. The website is the primary sales channel for the company. Which classification criteria should the analyst use to determine the severity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.