
EC-CouncilCertified SOC Analyst
Domain 3Objective 1
Log Management and Correlation CSA Practice Questions (Page 3)
Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
10concepts
Questions 11–15
- 11
A SOC team is deploying a SIEM and wants to ensure that the correlation engine can handle the expected log volume. They have a mix of high-volume network logs and low-volume application logs. What is the best way to configure the correlation engine?
Select an answer first - 12
A company is required to retain logs for 2 years for compliance, but the SIEM only has storage for 6 months. The team is considering archiving logs to a low-cost storage solution. However, the compliance team requires that archived logs be searchable within 24 hours. What is the best approach?
Select an answer first - 13
A SIEM is receiving logs from multiple sources, but the same event appears in different formats: Windows Event ID 4625, Linux auth.log 'Failed password', and a firewall 'authentication failed' message. The SOC wants to correlate these events as failed logins. What is the first step the team should take?
Select an answer first - 14
A SOC analyst is investigating a potential insider threat. The analyst needs to correlate user activity across multiple systems. Which combination of log sources would provide the most complete picture?
Select an answer first - 15
What is the primary purpose of log archival?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.