
EC-CouncilSOC Essentials
Domain 2Objective 3
Network-Based, Application-Based, and Host-Based Attacks SCE Practice Questions (Page 1)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
3concepts
Questions 1–5
- 1
A SOC analyst is monitoring network traffic and notices that a workstation is sending a large number of ARP replies claiming that its MAC address is the gateway's IP address. The analyst also sees that the workstation is receiving traffic that was destined for other hosts on the same subnet. Which attack is occurring, and what is the most effective mitigation?
Select an answer first - 2
A SOC analyst is investigating an alert on a Windows workstation. The analyst finds that a legitimate user account has been added to the local Administrators group, and a scheduled task has been created that runs a PowerShell script to download and execute a binary from an external IP address. The user denies making these changes. Which type of attack is most likely occurring, and what is the best immediate containment action?
Select an answer first - 3
A security administrator discovers that a user's workstation has been infected with ransomware. The ransomware encrypted the user's files and displayed a ransom note. The administrator has isolated the host. Which additional action should the administrator take to prevent the ransomware from spreading to other hosts?
Select an answer first - 4
A user reports that their online banking session was used to transfer money to an attacker's account. The user did not enter any credentials during the transfer. The bank's web application uses session cookies and does not validate the Referer header. Which attack likely occurred, and what is the BEST defense?
Select an answer first - 5
A user reports that their computer is running slowly and showing pop-up advertisements. The SOC analyst finds a suspicious browser extension that was installed without the user's knowledge. The extension has access to all websites the user visits. Which type of host-based attack is this, and what is the BEST immediate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.