Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 8Objective 4

Post-Incident Analysis and Reporting SCE Practice Questions (Page 10)

Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
6concepts

Questions 46–47

  1. 46expert · hard

    A post-incident analysis of a data exfiltration incident reveals multiple contributing factors: an unpatched vulnerability, a weak password, and a lack of network segmentation. The team must determine the primary root cause to prioritize fixes. Which approach is most appropriate?

    Select an answer first
  2. 47application · medium

    After a phishing incident, the SOC team found that the malware was delivered via a malicious attachment. The initial investigation stopped at 'the user clicked the attachment.' The team lead wants to uncover why the email bypassed the gateway and why the user was not blocked. Which approach best supports this deeper investigation?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to SCE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.