
EC-CouncilSOC Essentials
Domain 8Objective 1
Incident Handling Process SCE Practice Questions (Page 10)
Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 46–49
- 46
A SOC analyst receives an alert from the IDS about suspicious traffic to a known malicious IP address. The analyst checks the firewall logs and sees that the traffic originated from a single workstation. The workstation is used by the finance department. What should the analyst do to confirm the incident?
Select an answer first - 47
After a data breach, the incident response team has eradicated the malware and closed the vulnerability. They have restored the affected systems from backups and are ready to return them to production. However, the business wants to minimize downtime and is pressuring the team to reconnect the systems immediately. What should the team do?
Select an answer first - 48
Which of the following correctly lists the six phases of the incident handling process in the order they are typically performed?
Select an answer first - 49
What is the purpose of preserving evidence during incident handling?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SCE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.