
EC-CouncilCertified SOC Analyst
Domain 4Objective 1
Incident Detection with SIEM CSA Practice Questions (Page 2)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
50questions here
10free pages
8concepts
Questions 6–10
- 6
What does the 'severity' of a SIEM alert indicate?
Select an answer first - 7
A SOC analyst is triaging a queue of alerts. The alerts are: (1) a failed login on a domain controller, (2) a successful login from an unusual geographic location for a standard user, (3) a malware signature match on an isolated test server, and (4) a spike in outbound traffic from a database server that stores customer data. Which alert should the analyst prioritize first?
Select an answer first - 8
A company is evaluating whether to deploy a SIEM solution. The company has a small IT team and a limited budget. The security team wants to centralize logs from firewalls, servers, and endpoints, and to receive alerts for suspicious activities. Which consideration is most important when choosing a SIEM?
Select an answer first - 9
A SOC analyst is reviewing the SIEM architecture for a mid-sized company that has recently deployed a next-generation firewall, an endpoint detection and response (EDR) tool, and a custom line-of-business application. The analyst needs to ensure that security events from all three sources are available for correlation and alerting. Which action is most appropriate to achieve this goal?
Select an answer first - 10
Which of the following is a common method for ingesting logs into a SIEM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.