
EC-CouncilSOC Essentials
Domain 4Objective 2
SOC Architecture and Infrastructure SCE Practice Questions (Page 5)
Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 21–25
- 21
During a major incident, a SOC team is split between containing the threat and preserving forensic evidence. The incident is spreading rapidly, and the team must decide whether to isolate affected systems immediately or first collect volatile data. Which approach best balances containment and evidence preservation?
Select an answer first - 22
A SOC is implementing a new incident response workflow. The team wants to ensure that the right people are notified and involved at each stage of an incident. Which component of the SOC is most critical to define this?
Select an answer first - 23
Which of the following is NOT one of the three core components of a SOC?
Select an answer first - 24
What is the primary purpose of a ticketing system in a SOC?
Select an answer first - 25
A SOC is experiencing a high volume of SIEM alerts, many of which are false positives. Analysts are overwhelmed and missing critical alerts. The team wants to improve alert quality without losing visibility. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.