
EC-CouncilSOC Essentials
Domain 6Objective 1
SIEM Use Case Development SCE Practice Questions (Page 6)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
8concepts
Questions 26–30
- 26
A SOC team is building a use case to detect account takeover by monitoring for impossible travel. They have authentication logs, VPN logs, and physical access logs. However, the team is concerned about false positives from users who use VPNs or proxy services. Which data source combination is most effective to reduce false positives?
Select an answer first - 27
A SOC analyst is building a correlation rule to detect a potential Kerberoasting attack. The available logs include Windows Security logs (Event ID 4769) and Active Directory audit logs. Which correlation logic best detects Kerberoasting while minimizing false positives?
Select an answer first - 28
A SOC analyst is developing a use case for detecting credential dumping on Windows endpoints. They have access to Windows Security logs, Sysmon logs, and PowerShell logs. Which threat scenario should the use case focus on to best detect credential dumping?
Select an answer first - 29
A SOC analyst is developing a use case to detect data exfiltration via DNS tunneling. The organization has DNS logs, proxy logs, and NetFlow data. Which data source combination is most essential for this use case?
Select an answer first - 30
Which step in the SIEM use case development process involves adjusting the rule to reduce false positives?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.