Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 3Objective 1

Log Management and Correlation CSA Practice Questions (Page 4)

Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
10concepts

Questions 16–20

  1. 16application · medium

    A financial company must retain security logs for at least one year to meet regulatory requirements. The SIEM storage is expensive, and the team wants to keep the SIEM fast. What is the best approach?

    Select an answer first
  2. 17application · medium

    A healthcare organization is subject to HIPAA, which requires retaining audit logs for six years. The SIEM has limited storage, and the team wants to keep the SIEM operational. What is the best approach?

    Select an answer first
  3. 18foundation · easy

    Which correlation technique is most appropriate for detecting a multi-step attack such as a user downloading a malicious attachment and then executing it?

    Select an answer first
  4. 19application · medium

    A SOC team is configuring a SIEM correlation engine to process logs from multiple sources in real time. They notice that the correlation engine is missing events because the input queue is full. What should they do first?

    Select an answer first
  5. 20foundation · easy

    Which scenario best illustrates the value of log correlation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.