
EC-CouncilCertified SOC Analyst
Domain 4Objective 1
Incident Detection with SIEM CSA Practice Questions (Page 9)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
50questions here
10free pages
8concepts
Questions 41–45
- 41
A threat hunter wants to find any host that has communicated with a newly discovered malicious domain. The domain is not yet in the SIEM's threat intelligence feed. What is the most efficient way to search for this indicator?
Select an answer first - 42
Which of the following is a common log source that provides information about network traffic and blocked connections?
Select an answer first - 43
A company ingests logs from multiple firewall vendors into its SIEM. The analyst wants to search for all outbound connections to a specific IP address across all firewalls. The raw logs have different field names (e.g., 'dst_ip', 'dest_addr', 'destination'). What is the most efficient way to enable a single search across all logs?
Select an answer first - 44
During an investigation, an analyst finds a suspicious IP address in a firewall log that communicated with an internal server. The analyst wants to determine if any other internal hosts communicated with that IP and if any malware signatures were triggered. Which SIEM capability should the analyst use?
Select an answer first - 45
A small company has separate logs from its firewall, antivirus, and Windows servers. The security team wants to detect a multi-stage attack that involves a malicious download, a connection to a command-and-control server, and then lateral movement. What is the primary reason to use a SIEM for this detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.