
EC-CouncilSOC Essentials
Domain 2Objective 4
Insider Attacks SCE Practice Questions (Page 5)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
4concepts
Questions 21–25
- 21
A system administrator notices that a long-tenured employee, who is about to be laid off, has started accessing project repositories at unusual hours and downloading source code archives. The employee has never had a performance issue. Which combination of indicators and mitigation is most appropriate?
Select an answer first - 22
An organization wants to reduce the risk of insider threats without hindering employee productivity. Which approach best balances security and usability?
Select an answer first - 23
A security team is designing a program to detect insider threats early. They want to focus on behavioral indicators that are most likely to precede a malicious action. Which of the following should they prioritize?
Select an answer first - 24
Which of the following is a common behavioral indicator of a potential insider threat?
Select an answer first - 25
A security team is building a user-behavior analytics (UBA) program to detect insider threats. They have a small budget and need to choose which data sources to feed into the system. Which combination of data sources provides the best coverage for insider-threat detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.