
EC-CouncilSOC Essentials
Domain 2Objective 3
Network-Based, Application-Based, and Host-Based Attacks SCE Practice Questions (Page 3)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
3concepts
Questions 11–15
- 11
A SOC analyst is investigating a series of alerts on a web application. The analyst finds that an attacker has been able to submit a form that changes the user's email address without the user's knowledge. The application uses a session cookie for authentication, but does not use any anti-CSRF tokens. The analyst also notices that the application is vulnerable to XSS in the search field. Which attack is the most likely cause of the email change, and what is the best mitigation?
Select an answer first - 12
A company's network has been experiencing intermittent connectivity issues. The SOC team discovers that an attacker has been performing ARP spoofing to intercept traffic between the gateway and several hosts. The team also finds that the attacker used the intercepted credentials to log into a server and install a backdoor. Which combination of attacks occurred, and what is the BEST overall mitigation strategy?
Select an answer first - 13
A SOC analyst is investigating a server that has been compromised. The analyst finds that an attacker used a known vulnerability in the web server software to gain a foothold, then used a separate exploit to gain root access. Which combination of host-based attacks occurred, and what is the BEST defense-in-depth approach?
Select an answer first - 14
A user downloads a file attachment from an email, and after opening it, the system starts running unauthorized processes and sending sensitive files to an external server. Which type of host-based attack is this?
Select an answer first - 15
A SOC analyst is reviewing endpoint logs and sees that a standard user account has successfully executed a command that requires administrative privileges. The analyst checks the system and finds that the user is a member of the local Administrators group, which is unusual. Which type of host-based attack is this, and what is the BEST long-term remediation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.