
EC-CouncilSOC Essentials
Domain 2Objective 3
Network-Based, Application-Based, and Host-Based Attacks SCE Practice Questions (Page 8)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
3concepts
Questions 36–40
- 36
A SOC analyst is reviewing network logs and notices that an internal host is sending a large number of ICMP echo requests to a broadcast address. The analyst suspects a Smurf attack. Which mitigation would be MOST effective in preventing the network from being used as an amplifier?
Select an answer first - 37
A SOC analyst is reviewing a web application and notices that the application uses a hidden form field to store the user's role (e.g., 'user' or 'admin'). The analyst suspects that an attacker could modify this field to escalate privileges. Which attack is the analyst most concerned about, and what is the best mitigation?
Select an answer first - 38
An attacker submits the following input to a login form: `' OR '1'='1`. This input causes the application to return all user records instead of just the requested one. Which application-based attack is being performed?
Select an answer first - 39
A SOC analyst is reviewing web server logs and sees a request to a file upload endpoint that contains a filename with a path traversal payload: `../../../../etc/passwd`. The server responded with a 200 OK and the contents of the `/etc/passwd` file. Which attack is occurring, and what is the best mitigation?
Select an answer first - 40
A SOC analyst notices that a web application's login page is receiving a high volume of requests from many different IP addresses, each attempting to submit a small number of login attempts with credentials that appear to be from a recent data breach. The requests are coming from legitimate browsers and the application is not crashing, but the account lockout policy is being triggered for many legitimate users. Which type of attack is the analyst most likely observing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.