
EC-CouncilCertified SOC Analyst
Domain 4Objective 1
Incident Detection with SIEM CSA Practice Questions (Page 4)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
50questions here
10free pages
8concepts
Questions 16–20
- 16
What is the primary role of a Security Information and Event Management (SIEM) system in an organization's security operations?
Select an answer first - 17
Which of the following best describes how a SIEM contributes to incident detection?
Select an answer first - 18
An organization wants to detect a brute-force attack on its VPN gateway. The SOC analyst needs to create a correlation rule. Which condition should the rule use to minimize false positives while still detecting the attack?
Select an answer first - 19
A SOC analyst is configuring the SIEM to improve detection of known malicious domains. The team has subscribed to a threat intelligence feed that provides domain reputation scores. Which integration approach would most effectively use this feed?
Select an answer first - 20
A SOC analyst is investigating a potential compromise of a web server. The SIEM has logs from the web server, firewall, and threat intelligence feeds. The analyst has identified a suspicious IP that accessed a vulnerable endpoint. The analyst wants to determine if the same IP has been seen in other logs and if it is associated with any known malicious activity. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.