Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 4Objective 1

Incident Detection with SIEM CSA Practice Questions (Page 3)

Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.

50questions here
10free pages
8concepts

Questions 11–15

  1. 11foundation · easy

    Why is normalization important in a SIEM?

    Select an answer first
  2. 12foundation · easy

    What is the purpose of 'pivoting' during a SIEM investigation?

    Select an answer first
  3. 13application · medium

    A SOC analyst is triaging a queue of alerts. The organization has a critical financial database server and a less critical development server. The alerts are: (1) a failed login on the financial server, (2) a successful login from an unknown IP on the development server, (3) a malware signature match on a user workstation, and (4) a port scan from an internal IP. Which alert should be prioritized first?

    Select an answer first
  4. 14expert · hard

    A SOC manager wants to create a dashboard that shows the security posture of the organization. The dashboard should include the number of open alerts by severity, the top 10 attacked assets, and the average time to respond. However, the manager also wants to ensure that the dashboard is not overwhelming and provides actionable information. Which approach is best?

    Select an answer first
  5. 15foundation · easy

    When triaging SIEM alerts, which factor should be considered to prioritize which alert to investigate first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.