
EC-CouncilCertified SOC Analyst
Domain 3Objective 1
Log Management and Correlation CSA Practice Questions (Page 5)
Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
10concepts
Questions 21–25
- 21
What is the primary purpose of log correlation in a SIEM?
Select an answer first - 22
When configuring a correlation rule in a SIEM, what is the typical purpose of setting a time window?
Select an answer first - 23
Which sequence correctly represents the log lifecycle in a typical log management process?
Select an answer first - 24
A SOC wants to detect a user account that has been compromised and is being used to access multiple systems. The SIEM has authentication logs from all systems. Which correlation rule technique would be most effective?
Select an answer first - 25
What is the role of a correlation engine in a SIEM platform?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.