Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 3Objective 2

SOC Team Roles and Responsibilities SCE Practice Questions (Page 4)

Part of the Introduction to the Security Operations Center domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
5concepts

Questions 16–20

  1. 16expert · hard

    A SOC operates with three shifts. During a shift handover, the outgoing Tier 2 analyst provides a detailed verbal briefing to the incoming Tier 2 analyst about an ongoing incident. However, the incoming analyst later finds that the incident ticket lacks key details, such as the specific actions taken and the current containment status. What is the most likely cause of this issue?

    Select an answer first
  2. 17expert · hard

    A SOC has identified a sophisticated attack that evaded existing detection controls. The team suspects the attacker is still present and may have compromised multiple systems. The SOC manager needs to determine the full scope of the attack and identify any indicators of compromise that can be used to detect similar activity in the future. Which combination of roles is best suited to accomplish this?

    Select an answer first
  3. 18expert · hard

    During a major incident, the incident response team is overwhelmed with tasks. The forensic analyst is asked to help with containment, but this delays the forensic analysis. What is the best way to handle this conflict?

    Select an answer first
  4. 19application · medium

    A SOC shift is ending. The outgoing Tier 1 analyst has an open ticket about a suspicious PowerShell command on a workstation. The analyst has not yet determined if it is malicious. What should the analyst do during the handover?

    Select an answer first
  5. 20expert · hard

    A SOC team is responding to a critical incident. The incident response team is working with the IT team to contain the threat. The SOC manager wants to ensure that communication with external stakeholders is handled properly. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.