
EC-CouncilCertified SOC Analyst
Domain 4Objective 1
Incident Detection with SIEM CSA Practice Questions (Page 1)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
50questions here
10free pages
8concepts
Questions 1–5
- 1
A SOC team wants to enrich their SIEM alerts with threat intelligence data to provide context about the attacker. They have access to a commercial threat intelligence feed and an open-source feed. What is the best way to use these feeds?
Select an answer first - 2
A company is deploying a new SIEM. The SOC team has identified the following log sources: firewall, IDS/IPS, Windows servers, Linux servers, and cloud-based SaaS applications. The team is concerned about the volume of logs and the cost of storage. Which strategy would best balance log retention and cost?
Select an answer first - 3
Why are SIEM reports important for security operations?
Select an answer first - 4
A SIEM is receiving logs from a custom application that uses a non-standard log format. The analyst wants to search for a specific user ID in the logs. What must be done first to make the user ID searchable?
Select an answer first - 5
A SOC analyst is investigating an alert that was triggered by a SIEM rule that checks outbound connections against a threat intelligence feed. The alert shows a connection to an IP address that is listed as a C2 server. However, the analyst discovers that the IP address is a cloud provider's shared IP used by many legitimate customers. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.