Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 4Objective 1

Incident Detection with SIEM CSA Practice Questions (Page 10)

Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.

50questions here
10free pages
8concepts

Questions 46–50

  1. 46expert · hard

    A SOC team is designing a correlation rule to detect data exfiltration. The rule currently alerts on any outbound transfer greater than 100 MB from any host. This generates many false positives because some hosts regularly transfer large files for legitimate business purposes. The team wants to reduce false positives while still detecting exfiltration from critical servers. Which approach is most effective?

    Select an answer first
  2. 47application · medium

    A company has a mix of on-premises servers and cloud-based applications. The SOC wants to centralize security logs from both environments into the SIEM. Which approach is most appropriate?

    Select an answer first
  3. 48foundation · easy

    What is the primary purpose of a SIEM dashboard?

    Select an answer first
  4. 49foundation · easy

    How does integrating threat intelligence feeds into a SIEM improve detection?

    Select an answer first
  5. 50expert · hard

    A SOC team has a correlation rule that triggers on 'multiple failed logins followed by a successful login' for any account. The rule is generating a high number of false positives because users often mistype their passwords. The team wants to reduce false positives without missing real brute-force attacks. Which change is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.