
EC-CouncilSOC Essentials
Domain 2Objective 4
Insider Attacks SCE Practice Questions (Page 4)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
4concepts
Questions 16–20
- 16
A security team is investigating a potential insider threat. They have identified an employee who has access to sensitive data and has recently exhibited several behavioral indicators: working late, downloading large files, and expressing dissatisfaction with the company. However, the employee's manager says the employee is working on a legitimate project that requires after-hours access and large data transfers. Which of the following is the best course of action?
Select an answer first - 17
A company is implementing an insider threat program and wants to identify potential risks early. Which of the following is a common motivation for insider attacks that the program should monitor?
Select an answer first - 18
A company is considering implementing a user activity monitoring (UAM) system to detect insider threats. The system would record all user actions, including emails, file access, and web browsing. The company is concerned about employee privacy and legal implications. Which of the following approaches best balances the need for security with employee privacy concerns?
Select an answer first - 19
A user at a law firm clicks a link in a phishing email and enters their credentials. The attacker then uses those credentials to access client files. Which type of insider threat does this scenario represent, and what is the most important mitigation to prevent recurrence?
Select an answer first - 20
A company is merging with another firm. During the transition, several employees from the acquired company have been given access to the parent company's systems. Which insider-threat risk is most elevated, and what is the most effective mitigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.