
EC-CouncilCertified SOC Analyst
Domain 4Objective 1
Incident Detection with SIEM CSA Practice Questions (Page 8)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
50questions here
10free pages
8concepts
Questions 36–40
- 36
A SOC team wants to reduce the number of false positives from a SIEM correlation rule that alerts on any connection to a domain that appears on a free threat intelligence list. The list is updated daily and contains many domains that are commonly used by legitimate ad networks. What is the best way to improve the rule's precision?
Select an answer first - 37
What is the primary purpose of a correlation rule in a SIEM?
Select an answer first - 38
A SOC analyst notices that a correlation rule designed to detect 'multiple failed logins followed by a successful login' is generating too many false positives. The rule currently triggers on 5 failed logins within 10 minutes followed by a successful login. Which adjustment is most likely to reduce false positives?
Select an answer first - 39
A SOC analyst is investigating a potential brute-force attack. The SIEM has ingested logs from a firewall, a Windows domain controller, and a Linux authentication server. Each source uses a different timestamp format and field naming convention. The analyst wants to correlate failed login attempts across all sources in a single query. What should the analyst do first?
Select an answer first - 40
What is a 'use case' in the context of SIEM correlation rules?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.