
EC-CouncilCertified SOC Analyst
Domain 4Objective 1
Incident Detection with SIEM CSA Practice Questions (Page 5)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
50questions here
10free pages
8concepts
Questions 21–25
- 21
A SOC analyst notices that the SIEM is generating a high volume of alerts for a rule that triggers on any outbound connection to a known-bad IP address. The rule is currently applied to all firewall logs. The analyst wants to reduce false positives while still detecting the malicious activity on critical assets. What should the analyst do?
Select an answer first - 22
During an investigation, an analyst finds a suspicious file hash in an endpoint log. The analyst wants to determine if any other hosts in the environment have seen this file. Which SIEM capability should the analyst use?
Select an answer first - 23
A SOC analyst is integrating a threat intelligence feed into the SIEM. The feed provides IP addresses, domains, and file hashes. The analyst wants to use this feed to enrich alerts and improve detection. However, the analyst is concerned about the volume of alerts generated by the feed. Which approach is best?
Select an answer first - 24
A SOC analyst is triaging an alert that indicates a possible data exfiltration from a file server. The alert was generated by a correlation rule that detected a large outbound transfer from the file server to an external IP. The file server contains sensitive customer data. The analyst has verified that the external IP is not on any threat intelligence list and that the transfer occurred during business hours. What should the analyst do?
Select an answer first - 25
A SOC manager wants a single view that shows the current number of open alerts by severity, the top 10 source IPs generating alerts, and the trend of alerts over the last 24 hours. What should the analyst build?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.