
EC-CouncilCertified SOC Analyst
Domain 4Objective 1
Incident Detection with SIEM CSA Practice Questions (Page 6)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
50questions here
10free pages
8concepts
Questions 26–30
- 26
What is proactive threat hunting in the context of SIEM?
Select an answer first - 27
A SOC analyst is performing proactive threat hunting. The analyst has a hypothesis that attackers are using PowerShell to download and execute payloads. The SIEM has logs from Windows Event Logs (including PowerShell logging), network proxy logs, and threat intelligence feeds. Which approach would be most effective to validate the hypothesis?
Select an answer first - 28
A SOC manager wants to communicate the organization's security posture to executives. The manager needs to show the number of incidents by type, the average time to respond, and the percentage of alerts that were false positives. What is the best way to present this information?
Select an answer first - 29
A SOC manager wants to create a report that shows the effectiveness of the SOC in detecting and responding to incidents. The report should include metrics such as the number of alerts, the number of false positives, the average time to respond, and the number of incidents escalated. Which approach is best?
Select an answer first - 30
A company has a mix of on-premises servers and cloud-based applications. The SOC wants to ingest logs from both environments into a single SIEM. What is the most important consideration when setting up log collection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.