
EC-CouncilSOC Essentials
Domain 2Objective 5
Malware, Phishing, and Social Engineering SCE Practice Questions (Page 1)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
9concepts
Questions 1–5
- 1
A company wants to reduce the risk of social engineering attacks, but they have a limited budget. They currently have no security awareness training. Which initiative should they prioritize?
Select an answer first - 2
Which of the following is an effective measure to reduce the risk of social engineering attacks?
Select an answer first - 3
Which type of malware is designed to replicate itself and spread to other computers without requiring a host file to attach to?
Select an answer first - 4
An attacker sends an email with a PDF attachment that, when opened, exploits a vulnerability in the PDF reader to install malware. Which malware delivery mechanism is this?
Select an answer first - 5
A security analyst is reviewing a phishing email that targeted the CFO. The email appears to be from the CEO and contains a request to wire funds urgently. The email has a spoofed sender address and a link to a fake login page. Which combination of phishing techniques is being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.