
EC-CouncilSOC Essentials
Domain 8Objective 4
Post-Incident Analysis and Reporting SCE Practice Questions (Page 3)
Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
6concepts
Questions 11–15
- 11
A SOC analyst is writing the final incident report for a ransomware event. The report must be useful to both the executive leadership and the technical response team. Which section structure best serves both audiences?
Select an answer first - 12
Which of the following should be included in a lessons learned document to make it most useful for future incident response?
Select an answer first - 13
During a post-incident analysis of a server compromise, the team finds that the server was missing critical patches, the vulnerability scanner was not configured to check that server, and the patch management process had no follow-up for failed patches. Which root cause technique would best help the team identify the underlying process failure?
Select an answer first - 14
What is the primary purpose of conducting a post-incident analysis after a security incident has been contained and eradicated?
Select an answer first - 15
A SOC team is documenting lessons learned from an incident where the on-call analyst was not notified because the alert was routed to an outdated email distribution list. Which lesson-learned entry is most actionable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.