
EC-CouncilSOC Essentials
Domain 4Objective 2
SOC Architecture and Infrastructure SCE Practice Questions (Page 4)
Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 16–20
- 16
What does a SOC maturity model describe?
Select an answer first - 17
A SOC has moved from reactive alert handling to proactive threat hunting and has automated many detection and response processes. The team regularly reviews and improves its workflows. Which maturity stage does this SOC most likely represent?
Select an answer first - 18
A SOC manager wants to measure how quickly the team detects and responds to security incidents. Which pair of KPIs would directly provide this insight?
Select an answer first - 19
During a security incident, a SOC analyst identifies a compromised endpoint and needs to stop the spread while preserving evidence. According to the typical incident response workflow, which action should the analyst perform FIRST?
Select an answer first - 20
A SOC is planning its data storage architecture and needs to ensure that logs are retained for a specific period to meet compliance requirements. Which layer of the SOC infrastructure is primarily responsible for log retention and archival?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.