
EC-CouncilSOC Essentials
Domain 6Objective 1
SIEM Use Case Development SCE Practice Questions (Page 3)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
8concepts
Questions 11–15
- 11
Why is documentation important for SIEM use cases?
Select an answer first - 12
A SOC team has developed a use case to detect lateral movement using pass-the-hash. They have tested it with a known attack tool and it triggers correctly. However, they are concerned about false positives from legitimate administrative tools that also use remote logon. What is the best validation approach?
Select an answer first - 13
A SOC team has developed a use case to detect lateral movement using remote PowerShell. They have tested it with a known attack tool and it triggered correctly. However, in production, the rule is missing detections because some endpoints do not forward PowerShell logs to the SIEM. The team has limited resources and cannot enable log forwarding on all endpoints immediately. What is the best approach to improve detection coverage?
Select an answer first - 14
A SOC team has developed a SIEM use case to detect data exfiltration via large outbound file transfers. The rule triggers when a single user uploads more than 500 MB to an external cloud storage service within 15 minutes. During validation, the rule fires correctly on a simulated exfiltration. However, in production it generates many false positives from a marketing team that regularly uploads large video files. The team cannot exclude the marketing team entirely because they are also at risk of insider threats. What is the best approach?
Select an answer first - 15
A SIEM use case for detecting malware beaconing is generating too many false positives from a legitimate application that periodically checks for updates. The SOC wants to reduce noise without missing real C2 traffic. Which tuning action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.