
EC-CouncilSOC Essentials
Domain 7Objective 5
Leveraging Threat Intelligence for Hunting SCE Practice Questions (Page 7)
Part of the Threat Intelligence and Hunting domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
9concepts
Questions 31–35
- 31
After a successful threat hunting engagement, the SOC team identifies a new TTP that was not previously documented in their threat intelligence. The team wants to ensure that future hunts can benefit from this discovery. Which action best supports the threat hunting feedback loop?
Select an answer first - 32
A financial services company has a mature SOC that already subscribes to a commercial threat intelligence feed. The SOC manager wants to add a source that provides raw, real-time indicators from a broad community of security researchers and incident responders, with minimal cost. The team plans to integrate this source into their SIEM for correlation with internal telemetry. Which type of source should they add?
Select an answer first - 33
What is the purpose of the threat hunting feedback loop?
Select an answer first - 34
A SOC analyst is investigating an alert that triggered on a known malicious IP address. The analyst checks the SIEM and finds that the IP address is associated with a legitimate cloud service used by the organization. What should the analyst do to reduce false positives in the future?
Select an answer first - 35
A threat hunting team is analyzing a recent intrusion where the attacker used a previously unknown malware variant. The team has identified the malware's file hash, but they have also observed the attacker's behavior, such as using PowerShell to download additional payloads and establishing persistence via scheduled tasks. The team wants to develop a more durable detection that will remain effective even if the malware file hash changes. Which approach should they focus on?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.