
EC-CouncilCertified SOC Analyst
Domain 3Objective 1
Log Management and Correlation CSA Practice Questions (Page 1)
Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
10concepts
Questions 1–5
- 1
Which correlation technique is best suited for detecting a brute-force attack where an attacker attempts many passwords in a short time?
Select an answer first - 2
During an investigation, an analyst needs to determine whether a user installed unauthorized software on their workstation. Which log source would provide the most direct evidence?
Select an answer first - 3
A SIEM is struggling to keep up with the volume of logs, causing delays in correlation. The team has already optimized the correlation rules. Which additional action would most effectively reduce the processing load?
Select an answer first - 4
A SOC analyst is developing a use case to detect malware propagation within the network. Which correlation rule would be most effective?
Select an answer first - 5
Which method is commonly used to collect logs from network devices such as routers and switches?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.