
EC-CouncilSOC Essentials
Domain 6Objective 1
SIEM Use Case Development SCE Practice Questions (Page 1)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
8concepts
Questions 1–5
- 1
A SOC is building a use case to detect an attacker using PowerShell to download and execute a payload from an external URL. They have Windows Event logs, PowerShell script block logs, and proxy logs. Which data source and field combination is most essential for this use case?
Select an answer first - 2
A SOC analyst is developing a use case to detect a supply-chain attack where a legitimate software update is compromised. The organization has software inventory logs, file integrity monitoring (FIM) logs, and network logs. Which threat scenario should the use case focus on to best detect this attack?
Select an answer first - 3
A SOC analyst is tasked with building a SIEM use case to detect internal reconnaissance where an attacker enumerates SMB shares across multiple hosts. The analyst has access to Windows Security logs, DNS logs, and firewall logs. Which approach best aligns with the use case development process?
Select an answer first - 4
A SIEM rule that detects multiple failed logons followed by a successful logon is producing a high number of false positives because a specific application service account regularly locks out. The account is known to be non-interactive and is used by a legacy system. How should the analyst tune this use case?
Select an answer first - 5
What is the purpose of threat modeling in the context of SIEM use case development?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.