
EC-CouncilSOC Essentials
Domain 3Objective 3
SOC KPIs, Metrics, and Maturity Models SCE Practice Questions (Page 1)
Part of the Introduction to the Security Operations Center domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
5concepts
Questions 1–5
- 1
A SOC reports a high number of alerts per day, but the false positive rate is also high. Which of the following is the most appropriate conclusion from these metrics?
Select an answer first - 2
A SOC director is preparing a quarterly report for executive leadership. The report must show whether the SOC is meeting its goal of containing high-severity incidents within 30 minutes of detection. Which KPI should be highlighted?
Select an answer first - 3
What is the primary difference between a KPI and a metric in a SOC context?
Select an answer first - 4
A SOC analyst notices that the number of alerts has doubled, but the number of confirmed incidents has stayed the same. The analyst suspects the increase is due to a new detection rule. Which metric would best confirm this suspicion?
Select an answer first - 5
A SOC manager is using a maturity model to assess the SOC. The SOC has a well-defined incident response plan, but the plan is not consistently followed because analysts lack training. The manager must decide whether to invest in training or in a new automation tool. Which decision best addresses the root cause of the maturity gap?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.