Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 2Objective 2

Tactics, Techniques, and Procedures (TTPs) SCE Practice Questions (Page 1)

Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
4concepts

Questions 1–5

  1. 1expert · hard

    A threat intelligence report describes an adversary that uses a specific technique for initial access (spear-phishing) and a specific procedure for persistence (creating a registry run key). The SOC wants to implement a detection strategy that is resilient to changes in the adversary's malware. Which approach is most effective?

    Select an answer first
  2. 2application · medium

    A SOC analyst is reviewing an alert about a suspicious process that spawned a command prompt and then made an outbound connection to an IP address known to be a command-and-control (C2) server. The analyst wants to determine if this is a true positive and understand the full scope of the attack. Which action best uses TTPs to support the investigation?

    Select an answer first
  3. 3application · medium

    A company has experienced multiple phishing attacks that used different malware families but the same lure themes and delivery infrastructure. The SOC wants to improve their proactive defenses. Which approach best leverages TTPs to reduce the impact of future attacks?

    Select an answer first
  4. 4expert · hard

    A SOC is analyzing an adversary that uses a legitimate remote administration tool (RAT) for command and control. The RAT is commonly used by IT administrators, so the SOC cannot simply block it. The adversary uses the RAT to execute commands and move laterally. Which detection strategy best leverages TTPs to identify this adversary's activity?

    Select an answer first
  5. 5expert · hard

    A SOC team is evaluating detection coverage for a threat group that uses a variety of living-off-the-land binaries (LOLBins) to perform discovery and lateral movement. The team has limited resources and must choose between two detection strategies: (A) create signatures for the specific command-line patterns observed in past incidents, or (B) create behavioral rules that detect the underlying techniques, such as remote service creation and network share enumeration. Which strategy is more effective for long-term detection of this threat group?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.