
EC-CouncilSOC Essentials
Domain 2Objective 3
Network-Based, Application-Based, and Host-Based Attacks SCE Practice Questions (Page 6)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
3concepts
Questions 26–30
- 26
A company has a mix of Windows and Linux servers. The SOC team has detected a host-based attack where a process is running with root privileges on a Linux server, but the process was started by a non-root user. The team suspects a kernel vulnerability was exploited. The server is business-critical and cannot be rebooted during business hours. Which action should the team take to balance security and availability?
Select an answer first - 27
A SOC analyst is reviewing web server logs and sees a request to a search endpoint that contains the following URL-encoded parameter: `q=1%27%20OR%20%271%27%3D%271`. The application returned an HTTP 200 response with a database error message in the body. Which attack technique is being attempted, and what is the most immediate next step for the analyst?
Select an answer first - 28
A SOC team is responding to a ransomware incident. The ransomware has encrypted files on several servers and workstations. The team has isolated the affected hosts, but they are unsure how the ransomware initially gained access. The logs show that a user clicked a phishing link and entered their credentials on a fake login page. The user's account had administrative rights on several servers. Which combination of attack types occurred, and what is the MOST effective long-term prevention?
Select an answer first - 29
A SOC analyst is investigating a report of slow network performance. The analyst captures traffic and sees a large number of UDP packets sent to a single IP address, with the source IP spoofed to be the company's DNS server. The packets are directed at port 53 of the victim. Which attack is this, and what is the primary purpose of spoofing the source IP?
Select an answer first - 30
A SOC analyst is investigating an incident where an attacker intercepted a user's session cookie and used it to access the user's account. The analyst discovers that the application uses HTTP without TLS and sets cookies without the Secure flag. The application also allows session IDs to be passed in the URL. Which combination of weaknesses allowed this attack, and what is the BEST remediation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.