Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 2Objective 2

Tactics, Techniques, and Procedures (TTPs) SCE Practice Questions (Page 4)

Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
4concepts

Questions 16–20

  1. 16expert · hard

    A SOC team is designing a detection strategy for a new threat group that is known to use a variety of techniques, including spear-phishing, drive-by compromise, and exploitation of public-facing applications. The team has limited resources and must prioritize which techniques to build detections for. Which approach best balances coverage and resource constraints?

    Select an answer first
  2. 17application · medium

    A SOC team is reviewing a threat intelligence report that describes an adversary's TTPs. The report indicates the adversary uses a specific technique for initial access and a specific procedure for persistence. How can the SOC best use this information to improve their detection capabilities?

    Select an answer first
  3. 18application · medium

    A SOC analyst is analyzing a series of alerts. In one alert, an attacker used a legitimate remote desktop tool to connect to a server and then ran a script to disable security software. In another alert, the same attacker used a different remote desktop tool but the same script to disable security software. Which TTP component is most useful for correlating these two alerts as the same adversary?

    Select an answer first
  4. 19application · medium

    A company has experienced multiple ransomware incidents. In each case, the attacker gained access via a phishing email, used PowerShell to enumerate the network, and then deployed ransomware via scheduled tasks. The SOC wants to implement proactive defenses. Which of the following best applies TTP knowledge to prevent future incidents?

    Select an answer first
  5. 20foundation · easy

    Why do security analysts study TTPs rather than only focusing on individual indicators of compromise (IOCs)?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.