Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 3Objective 1

Log Management and Correlation CSA Practice Questions (Page 6)

Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
10concepts

Questions 26–30

  1. 26application · medium

    A SOC team needs to centralize logs from 200 Windows servers, 50 Linux servers, and several network appliances. The SIEM is hosted in a cloud environment, and the team wants to minimize the configuration burden on each source while ensuring logs are sent securely. Which approach should they use?

    Select an answer first
  2. 27foundation · easy

    Which correlation use case is most appropriate for detecting a brute-force attack on a web application?

    Select an answer first
  3. 28application · medium

    A SIEM is receiving logs from a custom application that uses a non-standard timestamp format. The SOC cannot correlate events from this application with others. What should the team do?

    Select an answer first
  4. 29foundation · easy

    Which factor is most important when determining log retention periods?

    Select an answer first
  5. 30foundation · easy

    Which component of a SIEM is responsible for parsing raw log data into a normalized format?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.