Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 2Objective 2

Tactics, Techniques, and Procedures (TTPs) SCE Practice Questions (Page 2)

Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
4concepts

Questions 6–10

  1. 6application · medium

    A SOC manager wants to improve the team's incident response process. The team often spends time identifying the scope of an attack after the initial alert. Which of the following best demonstrates the value of TTPs in improving incident response?

    Select an answer first
  2. 7application · medium

    During a threat hunt, an analyst discovers that an attacker used a legitimate Windows tool (e.g., `rundll32.exe`) to execute a malicious DLL that then created a scheduled task for persistence. The analyst wants to determine if this is part of a known campaign. Which of the following best uses TTPs to make that determination?

    Select an answer first
  3. 8expert · hard

    An organization has been targeted by an adversary that uses a specific technique for persistence (creating a new user account) and a specific procedure for lateral movement (using RDP to a specific server). The SOC has limited resources and must choose between two detection strategies: (1) monitoring for new user account creation, or (2) monitoring for RDP connections to the specific server. Which strategy is more effective for detecting the adversary's lateral movement behavior?

    Select an answer first
  4. 9expert · hard

    A SOC is reviewing a threat intelligence report that describes an adversary's TTPs. The report indicates the adversary uses a specific technique for defense evasion (disabling security tools) and a specific procedure for exfiltration (using FTP to a specific server). The SOC wants to implement a detection strategy that is resilient to changes in the adversary's malware. Which approach is most effective?

    Select an answer first
  5. 10expert · hard

    An organization has been targeted by an adversary that uses a specific technique for initial access (exploiting a public-facing application) and a specific procedure for persistence (modifying a service configuration). The SOC has limited resources and must choose between two detection strategies: (1) monitoring for the specific service configuration change, or (2) monitoring for exploitation attempts against the public-facing application. Which strategy is more effective for detecting the adversary's persistence behavior?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.