
EC-CouncilCertified Cybersecurity Technician
Domain 6Objective 3
Network Logs Monitoring and Analysis CCT Practice Questions (Page 3)
Part of the Network Monitoring and Troubleshooting domain, which makes up ~14% of our current practice bank.
56questions here
12free pages
10concepts
Questions 11–15
- 11
An analyst is loading logs from a firewall (text-based), a Windows server (Event Log), and a Linux application (JSON) into a SIEM. The SIEM requires all logs to have a common timestamp format and field names. What is the first step the analyst should perform?
Select an answer first - 12
Which log format is commonly used by network devices such as routers and switches to send event messages to a central logging server?
Select an answer first - 13
During an investigation, an analyst finds: (1) a firewall log showing an outbound connection to a known malicious IP, (2) a DNS log showing a query for a suspicious domain, and (3) an endpoint log showing a process executing a script. Each event occurred within two minutes. What does this correlation most likely indicate?
Select an answer first - 14
A healthcare organization must retain patient access logs for six years per regulation. They currently store logs on a local server with no redundancy. What should they implement to meet compliance while protecting log integrity?
Select an answer first - 15
A network administrator is troubleshooting intermittent connectivity issues. The firewall logs show dropped packets, the switch logs show CRC errors, and the server logs show TCP retransmissions. What is the most likely root cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.