
EC-CouncilSOC Essentials
Domain 6Objective 5
Incident Escalation and Ticketing Systems SCE Practice Questions (Page 9)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 41–45
- 41
A SOC analyst has been investigating a suspicious PowerShell command on a server. The analyst has determined it is likely malicious and has isolated the server. The analyst needs to escalate to L2, but the L2 team is currently handling another critical incident. The analyst's shift is ending in 30 minutes. What is the best course of action?
Select an answer first - 42
A SOC analyst is monitoring a SIEM dashboard and sees a spike in failed login attempts against a domain controller. The source IP is internal and the account names are generic service accounts. The analyst has not yet confirmed whether any login succeeded. What should the analyst do?
Select an answer first - 43
An L1 analyst has been working on a ticket for a malware infection. The analyst has removed the malware and verified the system is clean. The analyst marks the ticket as 'Resolved'. Later, the user reports that the system is still behaving strangely. What is the most appropriate action?
Select an answer first - 44
A SOC analyst has identified a critical vulnerability being exploited in the wild that affects the company's internet-facing servers. The analyst has confirmed the exploitation on one server. The escalation procedure states that the incident commander should be notified within 15 minutes of confirmation. The analyst has already spent 10 minutes documenting the findings in the ticket. What should the analyst do now?
Select an answer first - 45
A SOC analyst is triaging multiple tickets. Ticket A is a suspected phishing email that was delivered to 5 users, but no one has clicked. Ticket B is a confirmed malware infection on a single non-critical workstation. Ticket C is a potential data breach of a database containing customer PII, but the breach is not confirmed. The analyst has limited resources. Which ticket should be prioritized first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.