
EC-CouncilSOC Essentials
Domain 8Objective 3
Incident Response Lifecycle (preparation to Recovery) SCE Practice Questions (Page 4)
Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
7concepts
Questions 16–20
- 16
Which activity is most closely associated with the Identification phase?
Select an answer first - 17
After a security incident, the incident response team has completed eradication and is ready to begin the recovery phase. The affected systems include a web server and a database server. The team must restore these systems to normal operation while minimizing the risk of re-infection. Which recovery approach is best?
Select an answer first - 18
What is the primary goal of the Identification phase in incident response?
Select an answer first - 19
A company is preparing its incident response capability. The security team has limited resources and must decide where to focus their preparation efforts. They have identified that their main risk is phishing attacks leading to credential compromise. Which preparation activity is most aligned with this risk?
Select an answer first - 20
During an incident, the IR team identified that an attacker exploited an unpatched vulnerability in an internet-facing web server and installed a web shell. The team has isolated the server and is ready to remove the threat. Which action is part of the eradication phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.