Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 2Objective 3

Network-Based, Application-Based, and Host-Based Attacks SCE Practice Questions (Page 4)

Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
3concepts

Questions 16–20

  1. 16application · medium

    A web application allows users to upload profile pictures. The application stores the files on the server and serves them back with the original filename. An attacker uploads a file containing malicious JavaScript with an .html extension. When another user views the profile, the script executes. Which type of attack is this, and what is the BEST mitigation?

    Select an answer first
  2. 17foundation · easy

    A standard user account on a Windows workstation is able to run administrative commands and modify system settings that should require administrator privileges. Which type of host-based attack has likely occurred?

    Select an answer first
  3. 18expert · hard

    A company runs a public-facing web application behind a load balancer. The SOC team has observed a gradual increase in traffic that is causing intermittent availability issues. The traffic pattern shows a mix of HTTP GET requests for a specific API endpoint and a large number of TCP connections that complete the handshake but send no data. The source IPs are distributed across many countries. The team has limited budget and must maintain service availability. Which action should the team take FIRST?

    Select an answer first
  4. 19expert · hard

    A web application has been suffering from repeated SQL injection attempts. The development team has implemented parameterized queries, but the SOC team still sees malicious payloads in the logs. A deeper analysis reveals that the application also reflects user input in error messages without encoding, and the application uses a shared database account with elevated privileges. Which combination of issues is present, and what is the MOST comprehensive remediation?

    Select an answer first
  5. 20application · medium

    A network administrator discovers that an attacker has been intercepting and modifying traffic between a user's laptop and the company's mail server. The attacker used ARP spoofing to redirect traffic through their machine. Which additional security control would BEST prevent this type of attack from succeeding in the future?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.