Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 2Objective 1

Threat Intent, Motive, and Goal SCE Practice Questions (Page 6)

Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
4concepts

Questions 26–30

  1. 26expert · hard

    A company experiences a data breach where customer credit card numbers are stolen. The investigation reveals two possible attackers: a known cybercriminal group that typically sells stolen data, and a hacktivist group that has previously exposed corporate data to embarrass companies. The stolen data has not appeared on any public forum or dark web marketplace. Which attribution is more likely based on the threat intent and motive?

    Select an answer first
  2. 27application · medium

    A regional utility company discovers that an attacker has been slowly exfiltrating customer billing data over the past six months. The attacker used legitimate employee credentials obtained through a targeted phishing campaign against the finance department. The data has not been altered, and no ransomware or destructive activity has occurred. Based on the attacker's behavior, which threat motive and goal combination best characterizes this incident?

    Select an answer first
  3. 28application · medium

    A SOC analyst is reviewing an alert about a phishing campaign targeting employees at a defense contractor. The emails contain a link to a fake login page that mimics the company's VPN portal. The attacker's goal appears to be capturing VPN credentials. Which threat motive is most likely?

    Select an answer first
  4. 29expert · hard

    A SOC analyst is investigating an incident where a disgruntled employee deleted critical files from a file server. The employee had legitimate access and did not use any hacking tools. The deletion occurred over a weekend, and the employee has since resigned. Which combination of intent, motive, and goal best explains this insider threat?

    Select an answer first
  5. 30application · medium

    A SOC analyst observes an attacker who has gained access to a financial institution's network. The attacker is slowly exfiltrating customer account records over several weeks, while carefully avoiding detection by staying under threshold alerts. The attacker has not modified any files or disrupted any services. Which threat intent best describes this attacker's behavior?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.