
EC-CouncilSOC Essentials
Domain 8Objective 1
Incident Handling Process SCE Practice Questions (Page 4)
Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 16–20
- 16
A SOC analyst sees a spike in failed login attempts against a domain controller. The analyst checks the logs and sees that the attempts are coming from a single external IP address and have been ongoing for 30 minutes. No account has been compromised yet. What should the analyst do FIRST?
Select an answer first - 17
Which activity is part of the Eradication phase?
Select an answer first - 18
A company has just finished eradicating a web server compromise. The server has been rebuilt from a known-good image, and the vulnerability that was exploited has been patched. What should the team do next to complete the Recovery phase?
Select an answer first - 19
A post-incident review reveals that the SOC team did not have a clear escalation path, which delayed the response to a critical incident. What should the organization do to address this finding?
Select an answer first - 20
A phishing campaign successfully compromised three employee accounts, and the incident has been fully contained and eradicated. The CSIRT is now conducting a post-incident review. Which activity is most important during the Lessons Learned phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.