Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 7Objective 5

Leveraging Threat Intelligence for Hunting SCE Practice Questions (Page 9)

Part of the Threat Intelligence and Hunting domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
9concepts

Questions 41–45

  1. 41application · medium

    A threat intelligence analyst is tasked with setting up a process to continuously improve the quality of intelligence used by the SOC. The analyst wants to ensure that feedback from threat hunts is incorporated into future intelligence products. Which stage of the threat intelligence lifecycle should be formally updated with this feedback?

    Select an answer first
  2. 42application · medium

    A SOC analyst is correlating internal telemetry with a threat intelligence feed. The feed provides a list of malicious IPs, and the analyst finds that several internal hosts have communicated with these IPs. To reduce false positives, what should the analyst do before escalating?

    Select an answer first
  3. 43application · medium

    After a threat hunt, the SOC team discovers that a previously unknown variant of a known malware family is using a new file path and a different C2 protocol. The team wants to improve future hunts. What should they do?

    Select an answer first
  4. 44application · medium

    A threat intelligence report describes a new ransomware family that uses scheduled tasks to maintain persistence and communicates with a specific C2 domain. The SOC analyst wants to hunt for this ransomware in the environment. Which combination of telemetry would be most effective to correlate?

    Select an answer first
  5. 45expert · hard

    A threat hunter discovers a suspicious domain in DNS logs that matches an IOC from a commercial feed. The hunter wants to enrich the finding to determine if it is a real threat. The hunter has access to WHOIS, passive DNS, and a sandbox service. The hunter has limited time and must choose the most efficient enrichment method. Which method provides the most useful context for validation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.