
EC-CouncilSOC Essentials
Domain 2Objective 2
Tactics, Techniques, and Procedures (TTPs) SCE Practice Questions (Page 3)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
4concepts
Questions 11–15
- 11
A SOC is investigating a series of intrusions. In each case, the attacker used a different malware family, but the following behaviors were consistent: initial access via spear-phishing, use of scheduled tasks for persistence, and data exfiltration via DNS queries. The SOC has limited resources and must choose one detection strategy. Which strategy best leverages TTPs to detect future intrusions by this adversary?
Select an answer first - 12
An analyst is creating a threat profile for an adversary that uses USB drives to deliver malware, then uses a keylogger to capture credentials, and finally uses those credentials to access a cloud application. The analyst notes the adversary's objective is credential theft. Which of the following is correctly identified as a tactic?
Select an answer first - 13
During incident response, how can knowledge of TTPs aid in containing an active threat?
Select an answer first - 14
An analyst observes that an adversary sent a targeted email with a malicious attachment to a finance employee. After the attachment was opened, the adversary established a command-and-control (C2) channel. Which TTP components are demonstrated in this scenario?
Select an answer first - 15
A SOC team is reviewing a series of alerts where an attacker used a previously unknown malware variant to exfiltrate data over HTTPS. The team's signature-based IDS did not detect the malware, but the team noticed the attacker used the same command-line arguments and file paths as a known threat group. How can the team best improve detection for this specific adversary?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.