Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 3Objective 1

Log Management and Correlation CSA Practice Questions (Page 10)

Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
10concepts

Questions 46–48

  1. 46application · medium

    A SOC analyst notices that the SIEM is generating many false positives because the same event is logged in different formats by different devices. The analyst wants to ensure that all logs are stored in a consistent format for correlation. What should the analyst do?

    Select an answer first
  2. 47expert · hard

    A SOC team has a correlation rule that triggers on 'a user logging in from a new geolocation.' The rule is generating false positives because users travel frequently. The team wants to detect account compromise without annoying alerts. What is the best approach?

    Select an answer first
  3. 48foundation · easy

    What is the primary benefit of aggregating logs from multiple sources into a centralized repository?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.