
EC-CouncilSOC Essentials
Domain 2Objective 3
Network-Based, Application-Based, and Host-Based Attacks SCE Practice Questions (Page 2)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
3concepts
Questions 6–10
- 6
A developer is building a web form that allows users to change their email address. The form includes a hidden field with the user's ID. An attacker modifies the hidden field to another user's ID and submits the form, changing the victim's email address. Which type of attack is this, and what is the BEST defense?
Select an answer first - 7
A SOC analyst is investigating a workstation that is sending outbound connections to a known command-and-control server. The analyst finds a suspicious process running with SYSTEM privileges that was not started by any legitimate service. Which type of host-based attack is most likely occurring, and what is the FIRST step in containment?
Select an answer first - 8
A developer is reviewing code for a web application that allows users to search a product database. The search query is inserted directly into a SQL statement without parameterization. Which attack is the application vulnerable to, and what is the BEST fix?
Select an answer first - 9
A security analyst notices that an internal web server is receiving a high volume of TCP SYN packets from many different source IP addresses, but the server never sends a SYN-ACK response. The server's connection table is filling up, and legitimate users are experiencing timeouts. Which type of attack is most likely occurring, and what immediate mitigation should the analyst recommend?
Select an answer first - 10
A network engineer is setting up a new wireless network for a small office. The engineer wants to prevent attackers from capturing sensitive data transmitted over the air. Which combination of controls would BEST mitigate packet sniffing on the wireless network?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.