
EC-CouncilCertified Cybersecurity Technician
Domain 6Objective 3
Network Logs Monitoring and Analysis CCT Practice Questions (Page 6)
Part of the Network Monitoring and Troubleshooting domain, which makes up ~14% of our current practice bank.
56questions here
12free pages
10concepts
Questions 26–30
- 26
What is the primary purpose of a centralized log aggregation system?
Select an answer first - 27
An analyst notices a sudden spike in failed authentication attempts in the Windows Event Log, followed by a successful login from a foreign IP at 3 AM. Which manual analysis technique would best confirm whether this is a brute-force attack?
Select an answer first - 28
An analyst wants to identify all login failures across multiple servers and then determine if any were followed by a successful login from the same IP. Which analysis technique is most effective?
Select an answer first - 29
An analyst notices a spike in failed login attempts on the VPN gateway, followed by a successful login from the same IP address, and then a large data download from a file server. Which log analysis technique would best identify this as a potential attack chain?
Select an answer first - 30
A security team is evaluating log monitoring tools. They need to handle a high volume of logs, support complex queries, and provide real-time alerting. They also have a limited budget and prefer open-source solutions. Which tool would best meet these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.