Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 2Objective 4

Insider Attacks SCE Practice Questions (Page 3)

Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
4concepts

Questions 11–15

  1. 11application · medium

    A security analyst is reviewing a user's activity and finds that the user has been logging in from a remote location that is not typical for them, and the user's recent behavior includes downloading large amounts of data. The user's manager says the employee is on vacation. What should the analyst suspect?

    Select an answer first
  2. 12expert · hard

    A security analyst is investigating a potential insider threat. The user in question has access to sensitive data and has been exhibiting signs of financial stress. Which combination of behavioral indicators would most strongly suggest a malicious insider?

    Select an answer first
  3. 13expert · hard

    A security analyst at a financial firm is investigating a potential data exfiltration. The logs show that a senior trader's account was used to access a large number of client records and then transfer them to an external cloud storage service. The trader is known to be disgruntled after a recent bonus dispute. However, the analyst also notices that the trader's account had a failed login attempt from a foreign IP address just before the activity began. Which conclusion is most appropriate?

    Select an answer first
  4. 14expert · hard

    A mid-sized company has a small security team. They have a SIEM that generates many alerts, but the team cannot investigate all of them. They want to focus on insider threats. Which approach best balances detection coverage with the team's limited capacity?

    Select an answer first
  5. 15application · medium

    A financial analyst at a bank is observed logging into the customer relationship management system at 2:00 AM from the office, accessing records of high-net-worth clients, and emailing a spreadsheet to a personal webmail address. The analyst has no history of policy violations and had recently complained about a denied promotion. Which classification best describes this insider threat?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.