
EC-CouncilSOC Essentials
Domain 8Objective 4
Post-Incident Analysis and Reporting SCE Practice Questions (Page 4)
Part of the Incident Response and Handling domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 2–2 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
6concepts
Questions 16–20
- 16
After a phishing incident, the SOC team discovers that the initial malware was delivered through a malicious macro in an Excel file. The team wants to understand why the user opened the attachment despite security awareness training. They decide to use the 5 Whys technique. Which outcome best represents the correct application of this technique?
Select an answer first - 17
What is the ultimate goal of integrating lessons learned into security policies and procedures?
Select an answer first - 18
Which structured technique involves repeatedly asking 'why' to drill down from a symptom to the underlying cause of an incident?
Select an answer first - 19
Which root cause analysis tool visually organizes potential causes of an incident into categories such as people, process, technology, and environment?
Select an answer first - 20
After a ransomware incident, the SOC team learns that the backup restoration process was not tested regularly, which delayed recovery. The team wants to integrate this lesson into the organization's procedures. Which action is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.