
EC-CouncilSOC Essentials
Domain 2Objective 5
Malware, Phishing, and Social Engineering SCE Practice Questions (Page 4)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
9concepts
Questions 16–20
- 16
A company wants to reduce the risk of pretexting attacks, where attackers impersonate IT staff to obtain credentials. They have a helpdesk that sometimes needs to verify user identities over the phone. Which policy would best balance security and operational efficiency?
Select an answer first - 17
A company has experienced several social engineering incidents where employees were tricked into revealing passwords over the phone. Which combination of measures would most effectively reduce this risk?
Select an answer first - 18
A user reports that after visiting a legitimate news website, their browser redirected to an unknown page and then a file was downloaded automatically. The user did not click any links. The file, when executed, began encrypting files on the workstation. Which malware delivery mechanism and malware type best describe this incident?
Select an answer first - 19
How does multi-factor authentication (MFA) help protect against phishing attacks?
Select an answer first - 20
An attacker creates a fake scenario, such as claiming to be a contractor who needs to check the wiring, to gain physical access to a building. This social engineering vector is called:
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.