
EC-CouncilSOC Essentials
Domain 6Objective 5
Incident Escalation and Ticketing Systems SCE Practice Questions (Page 4)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 16–20
- 16
Which combination of factors is most commonly used to determine the priority of a security incident ticket?
Select an answer first - 17
In a typical ticket lifecycle, what does the 'resolved' state indicate?
Select an answer first - 18
In a typical SOC escalation hierarchy, which responsibility is most closely associated with Level 2 (L2) analysts?
Select an answer first - 19
A SOC analyst is triaging a ticket for a possible denial-of-service (DoS) attack on the company's public website. The website is currently slow but still accessible. The attack is ongoing. What priority should the analyst assign to this ticket?
Select an answer first - 20
A SOC analyst is monitoring a low-severity malware alert on a single non-critical workstation. The analyst has confirmed the malware is a known adware and has removed it. The workstation is used by a temporary contractor. Which of the following best describes the appropriate escalation decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.