
EC-CouncilSOC Essentials
Domain 6Objective 5
Incident Escalation and Ticketing Systems SCE Practice Questions (Page 3)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 11–15
- 11
A SOC analyst receives a ticket for a potential data breach involving a database with customer PII. The breach is suspected but not confirmed. The database is not publicly accessible, and there is no evidence of data exfiltration yet. What priority should the analyst assign to this ticket?
Select an answer first - 12
During a major incident, the SOC manager instructs the L1 analyst to escalate the incident to L3 and notify the CISO. The analyst has already created a ticket and documented the initial findings. What should the analyst do next?
Select an answer first - 13
Which communication channel is most appropriate for escalating a critical, time-sensitive incident to on-call SOC management?
Select an answer first - 14
A SOC analyst is using the ticketing system to manage a phishing incident. The analyst has created a ticket, assigned it to themselves, and is now investigating the email. Which action best illustrates the tracking function of the ticketing system?
Select an answer first - 15
A SOC analyst discovers that a critical internal application server is sending outbound traffic to an unknown IP address. The analyst has verified that the server is not supposed to communicate externally. The analyst has already created a ticket and is about to escalate. What is the most appropriate communication step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.