Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 3Objective 1

Log Management and Correlation CSA Practice Questions (Page 2)

Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
10concepts

Questions 6–10

  1. 6foundation · easy

    What is the purpose of log normalization in a SIEM environment?

    Select an answer first
  2. 7application · medium

    A newly deployed correlation rule is generating hundreds of alerts per day, most of which are false positives. The SOC team is overwhelmed. What is the most effective first step to improve the rule's precision?

    Select an answer first
  3. 8expert · hard

    A SOC is centralizing logs from remote branch offices with limited bandwidth. The SIEM is in a central data center. The team needs to ensure logs are not lost during network outages and that bandwidth usage is minimized. Which collection strategy best meets these conflicting requirements?

    Select an answer first
  4. 9application · medium

    A financial company must retain audit logs for at least 7 years to meet regulatory requirements. The SIEM's hot storage is expensive and limited. The company wants to keep recent logs easily searchable while preserving older logs for compliance. Which strategy best meets these needs?

    Select an answer first
  5. 10application · medium

    A SIEM is receiving logs from a custom application that uses a non-standard timestamp format. The analyst wants to ensure the SIEM can correlate these logs with other sources. What is the most important step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.