
EC-CouncilSOC Essentials
Domain 2Objective 4
Insider Attacks SCE Practice Questions (Page 7)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
4concepts
Questions 31–35
- 31
A mid-sized company is designing an insider threat mitigation program. They have a limited budget and must choose between two controls: (1) implementing user and entity behavior analytics (UEBA) to detect anomalies, or (2) deploying data loss prevention (DLP) to block unauthorized data transfers. The company's primary concern is preventing data exfiltration by malicious insiders, but they also want to detect compromised accounts. Which approach is most effective given the constraints?
Select an answer first - 32
A company discovers that a former employee, who was not properly offboarded, still has active credentials and used them to steal proprietary data. Which mitigation strategy would have most directly prevented this incident?
Select an answer first - 33
A financial analyst at a bank has been working late for weeks, is frequently seen copying large datasets to a personal USB drive, and recently received a poor performance review. The bank's DLP alerts show the analyst exporting customer records to an encrypted archive. Which type of insider threat best describes this behavior, and what is the most immediate containment step?
Select an answer first - 34
A user at a software company accidentally sends a spreadsheet containing customer email addresses to the wrong external recipient. The user immediately reports the mistake. Which type of insider threat is this, and what is the most appropriate response?
Select an answer first - 35
A security analyst is reviewing the behavior of an employee who has access to the company's intellectual property. The employee has recently been passed over for a promotion and has made negative comments about the company on social media. The analyst notices that the employee has been accessing files outside their normal work area and has been sending emails to a personal account. Which of the following is the most likely motivation for the employee's behavior?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.