
EC-CouncilSOC Essentials
Domain 7Objective 4
Threat Hunting Techniques and Methodologies SCE Practice Questions (Page 5)
Part of the Threat Intelligence and Hunting domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
9concepts
Questions 21–25
- 21
A SOC team is planning a hunt for a threat actor that is known to use both commodity malware and custom tools. The team has a limited time window and must decide between an IOC-based hunt and a hypothesis-driven hunt. Which approach is more likely to uncover the custom tools?
Select an answer first - 22
A hunt identifies a series of failed logon attempts followed by a successful logon from a foreign IP address. The user is a remote worker who frequently travels. The analyst must decide whether this is a true positive or a false positive. Which combination of factors would most strongly support a true positive?
Select an answer first - 23
During a hunt, an analyst identifies a series of PowerShell commands that download and execute a script from a remote server. The script is not flagged by antivirus, and the remote server is a known file-sharing site. What is the most appropriate next step?
Select an answer first - 24
An analyst is hunting for command-and-control (C2) activity in an environment where most hosts use dynamic DNS and cloud-based services. The analyst has DNS logs and proxy logs. Which technique would best reduce false positives while identifying potential C2?
Select an answer first - 25
A threat hunter is investigating a possible data breach that occurred two months ago. The organization only retains endpoint logs for 30 days, but network flow data is retained for one year. The hunter needs to determine if a specific workstation was compromised. Which approach is most feasible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.