Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 2Objective 3

Network-Based, Application-Based, and Host-Based Attacks SCE Practice Questions (Page 7)

Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
3concepts

Questions 31–35

  1. 31application · medium

    A SOC analyst is monitoring network traffic and sees that a workstation is sending a large number of TCP SYN packets to a server on port 80, but the server is not responding with SYN-ACK packets. The analyst also notices that the source IP address of the SYN packets is spoofed and changes frequently. Which attack is occurring, and what is the best mitigation?

    Select an answer first
  2. 32application · medium

    A security analyst is reviewing a web application that allows users to post comments. The analyst notices that the application reflects user input in the page without sanitization. An attacker could craft a URL that, when clicked by a victim, executes JavaScript in the victim's browser. Which type of attack is this, and what is the BEST mitigation?

    Select an answer first
  3. 33application · medium

    A SOC analyst is investigating a server that was compromised. The analyst finds a new user account with UID 0 on a Linux system, and the `/etc/passwd` file has been modified to grant this user a shell. The analyst also sees that the server is sending outbound connections to an IP address known to be a command-and-control server. Which type of attack is most likely, and what is the best immediate action?

    Select an answer first
  4. 34application · medium

    A SOC analyst is reviewing network traffic and sees a TCP handshake to a web server on port 443. The handshake completes, but then the client sends a series of incomplete HTTP requests that never finish. The server is consuming resources waiting for the requests to complete, and the analyst notices that many other clients are doing the same thing. Which attack is occurring, and what is the best mitigation?

    Select an answer first
  5. 35expert · hard

    A SOC analyst is investigating a compromised Linux server. The analyst finds a new user account with UID 0 and a modified `/etc/passwd` file. The analyst also sees that the server is sending outbound connections to an IP address on port 4444. The server is also running a web application that is vulnerable to SQL injection. Which attack is the most likely initial vector, and what is the best immediate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.