Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 7Objective 4

Threat Hunting Techniques and Methodologies SCE Practice Questions (Page 8)

Part of the Threat Intelligence and Hunting domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
9concepts

Questions 36–40

  1. 36foundation · easy

    Which hunting technique is most effective for detecting a new malware variant that has never been seen before?

    Select an answer first
  2. 37application · medium

    A SOC team wants to identify compromised endpoints that are beaconing to a known command-and-control (C2) domain. The team has access to firewall logs, DNS logs, and endpoint process creation logs. Which combination of data sources and hunting technique would be most effective?

    Select an answer first
  3. 38foundation · easy

    Which step in the threat hunting process involves validating that a finding is a true positive and not a false alarm?

    Select an answer first
  4. 39foundation · easy

    Which data source is most likely to provide evidence of command-and-control (C2) communication from an infected endpoint?

    Select an answer first
  5. 40application · medium

    A SOC analyst at a mid-sized financial firm is planning a threat hunt after a public report describes a new banking trojan that uses PowerShell to download a second-stage payload from a rarely-used file-sharing domain. The analyst wants to search for signs of this activity in the environment. Which approach best aligns with a hypothesis-driven hunt?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to SCE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.