
EC-CouncilSOC Essentials
Domain 7Objective 4
Threat Hunting Techniques and Methodologies SCE Practice Questions (Page 2)
Part of the Threat Intelligence and Hunting domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
9concepts
Questions 6–10
- 6
A threat intelligence report indicates that a specific adversary group is known to use scheduled tasks for persistence. The SOC team wants to hunt for this behavior in their environment. Which hypothesis is the most testable and actionable?
Select an answer first - 7
A SOC analyst is hunting for a possible insider threat who is exfiltrating data via encrypted web traffic. The analyst has proxy logs, DNS logs, and endpoint data. The encrypted traffic makes deep packet inspection impossible. Which hunting technique is most effective?
Select an answer first - 8
Which action is most appropriate when a threat hunter discovers an alert that appears suspicious but lacks enough evidence to confirm it as malicious?
Select an answer first - 9
A threat hunter wants to detect unusual network behavior that does not match any known attack signature. Which methodology is most appropriate?
Select an answer first - 10
A SOC team wants to automate the initial triage of hunting leads so analysts can focus on deeper investigation. They have a SIEM with a REST API and a ticketing system. Which automation approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.