
EC-CouncilCertified SOC Analyst
Domain 4Objective 1
Incident Detection with SIEM CSA Practice Questions (Page 7)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
50questions here
10free pages
8concepts
Questions 31–35
- 31
What is an example of a threat intelligence indicator that can be integrated into a SIEM?
Select an answer first - 32
A company is evaluating whether to deploy a SIEM. The security team's main goal is to detect an attack that spans multiple systems, such as a user clicking a malicious link, the malware downloading a payload, and then the payload communicating with a C2 server. Which SIEM feature is most important for this goal?
Select an answer first - 33
A SOC analyst is triaging an alert that was generated by a correlation rule. The rule triggered on a single failed login from an external IP to a domain controller, followed by a successful login from the same IP 5 minutes later. The domain controller is a critical asset. However, the analyst notices that the successful login was from a known VPN gateway IP, and the user is a remote employee who frequently works from home. What should the analyst do?
Select an answer first - 34
What is the purpose of parsing in a SIEM?
Select an answer first - 35
A SOC manager wants a daily overview of the number of security alerts by severity, the top attacked assets, and the average time to respond. Which SIEM feature should be used to present this information to management?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.