Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 8Objective 3

Incident Response Lifecycle (preparation to Recovery) SCE Practice Questions (Page 6)

Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
7concepts

Questions 26–30

  1. 26expert · hard

    After a major incident, the incident response team conducts a lessons learned review. The team identifies that the incident was not detected quickly because the SIEM rules were not tuned to the organization's environment. The team also found that the incident response plan did not include clear criteria for escalating to senior management. Which improvement should the team prioritize to address both issues?

    Select an answer first
  2. 27expert · hard

    A SOC analyst receives an alert about a user account performing a large number of file downloads from a file share. The user is a known employee, and the downloads are happening during business hours. The analyst must decide whether this is a potential incident. Which action is most appropriate for the identification phase?

    Select an answer first
  3. 28expert · hard

    An organization suffered a data breach through a compromised web server. The IR team has contained the server and identified that the attacker used a SQL injection vulnerability to access the database. The team must eradicate the root cause while minimizing downtime for the web application. Which approach is most effective?

    Select an answer first
  4. 29foundation · easy

    What is the primary purpose of the Lessons Learned phase?

    Select an answer first
  5. 30application · medium

    A SOC analyst receives an alert from the SIEM about a user account failing to authenticate multiple times from an unusual geographic location. The analyst checks the user's recent activity and sees that the account has not been used for several days. The analyst must determine whether this is a true incident. Which action is most appropriate for the identification phase?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.