Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 2Objective 1

Threat Intent, Motive, and Goal SCE Practice Questions (Page 7)

Part of the Fundamentals of Cyber Threats domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
4concepts

Questions 31–35

  1. 31application · medium

    A SOC analyst is examining a malware sample that was found on a workstation. The malware is designed to log keystrokes and capture screenshots, but it does not spread to other systems or cause any visible damage. The analyst determines that the malware is sending the captured data to an external server. What is the most likely threat intent?

    Select an answer first
  2. 32application · medium

    A SOC analyst is investigating a breach at a healthcare provider. The attacker used a vulnerability in the web application to upload a web shell, then used it to access the database containing patient records. The attacker copied the records and then deleted the web shell to cover their tracks. What is the most likely threat goal?

    Select an answer first
  3. 33expert · hard

    A financial institution detects two separate intrusions. Intrusion 1: An attacker used a phishing email to steal a trader's credentials and accessed the trading platform, but no trades were placed. Intrusion 2: An attacker exploited a vulnerability in the public-facing web server and defaced the login page with a political message. The SOC must determine which intrusion indicates a more serious threat. Which analysis is most accurate?

    Select an answer first
  4. 34application · medium

    A security analyst observes a threat actor defacing a government website with political slogans and posting a manifesto. No data was stolen, and no systems were damaged beyond the website content. Which combination of intent, motive, and goal best describes this attack?

    Select an answer first
  5. 35application · medium

    A security team notices that a competitor's website is repeatedly taken offline by distributed denial-of-service (DDoS) attacks during product launch events. The attacks are timed precisely to coincide with the competitor's marketing campaigns. Which threat motive is most likely driving this behavior?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.