
EC-CouncilCertified Cybersecurity Technician
Domain 6Objective 3
Network Logs Monitoring and Analysis CCT Practice Questions (Page 7)
Part of the Network Monitoring and Troubleshooting domain, which makes up ~14% of our current practice bank.
56questions here
12free pages
10concepts
Questions 31–35
- 31
An analyst is investigating a potential malware infection. Which combination of log sources would provide the most complete picture of the attack?
Select an answer first - 32
A user reports that they cannot access a web application. Which log source would you first examine to determine if the web server received the request?
Select an answer first - 33
A multinational company must comply with data residency regulations that require logs containing personal data to be stored within the country where the data originates. They currently use a centralized SIEM in a different country. What is the best way to handle this?
Select an answer first - 34
An analyst is investigating a data breach. The SIEM shows: (1) an authentication success for a privileged account at 2:00 AM, (2) a large data transfer from a database server to an external IP at 2:15 AM, and (3) the privileged account was disabled at 2:30 AM. What is the most likely sequence of events?
Select an answer first - 35
Which type of report is most useful for demonstrating compliance with a regulatory standard that requires quarterly review of security logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.