Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 8Objective 3

Incident Response Lifecycle (preparation to Recovery) SCE Practice Questions (Page 1)

Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
7concepts

Questions 1–5

  1. 1application · medium

    A small company is building its incident response capability. It has limited budget and no dedicated security staff. The management wants to be ready for common incidents like phishing and ransomware. Which preparation activity should the company prioritize?

    Select an answer first
  2. 2application · medium

    After a data breach, the incident response team completes the lessons learned phase. The team identifies that the incident response plan lacked clear escalation procedures, which caused delays. Which action should the team take to improve future response?

    Select an answer first
  3. 3foundation · easy

    Which activity is a key component of the Preparation phase in the incident response lifecycle?

    Select an answer first
  4. 4application · medium

    After a significant security incident, the incident response team completes the recovery phase and systems are back to normal. The team leader wants to ensure that the organization learns from the incident and improves its response capabilities. Which action is most aligned with the lessons learned phase?

    Select an answer first
  5. 5expert · hard

    A web server was compromised via a SQL injection vulnerability in a custom application. The incident response team contained the server by isolating it. During eradication, the team discovers that the attacker may have planted a backdoor in the application code. The team has a backup from before the compromise, but the backup may also contain the vulnerability. The team must decide how to eradicate the root cause while minimizing downtime. Which approach is best?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.