
EC-CouncilSOC Essentials
Domain 2Objective 1
Threat Intent, Motive, and Goal SCE Practice Questions (Page 1)
Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
4concepts
Questions 1–5
- 1
A SOC analyst is reviewing an alert about a brute-force attack on the company's email server. The attacker is trying many passwords against a single account. The analyst notices that the account belongs to an executive who has access to merger and acquisition plans. What is the most likely threat intent?
Select an answer first - 2
An analyst is reviewing an incident where an insider with administrative privileges copied a large database of customer records to a personal USB drive. The employee then resigned and joined a competitor. No systems were damaged, and no ransom was demanded. Which combination of intent, motive, and goal best explains this insider threat?
Select an answer first - 3
A SOC analyst is reviewing an alert about a distributed denial-of-service (DDoS) attack targeting a government website. The attack traffic originates from a botnet, and the website is intermittently unavailable. The attackers have not attempted to breach the network or steal data. What is the most likely threat goal?
Select an answer first - 4
A SOC analyst is investigating a breach at a media company. The attacker gained access through a phishing email, then spent weeks quietly downloading internal emails and unpublished articles. The attacker did not encrypt any files or demand a ransom. Later, the company discovers that a rival media outlet published several of the unpublished articles. Which combination of intent, motive, and goal best explains the attacker's actions?
Select an answer first - 5
A security team is analyzing a series of attacks on a media company. Attack 1: A DDoS attack took the company's streaming service offline during a major live event. Attack 2: A phishing campaign targeted employees with emails containing links to a fake login page. Attack 3: An attacker defaced the company's blog with a political statement. Which attack indicates the most sophisticated threat actor?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.