
EC-CouncilCertified SOC Analyst
Domain 3Objective 1
Log Management and Correlation CSA Practice Questions (Page 6)
Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
10concepts
Questions 26–30
- 26
A SOC team needs to centralize logs from 200 Windows servers, 50 Linux servers, and several network appliances. The SIEM is hosted in a cloud environment, and the team wants to minimize the configuration burden on each source while ensuring logs are sent securely. Which approach should they use?
Select an answer first - 27
Which correlation use case is most appropriate for detecting a brute-force attack on a web application?
Select an answer first - 28
A SIEM is receiving logs from a custom application that uses a non-standard timestamp format. The SOC cannot correlate events from this application with others. What should the team do?
Select an answer first - 29
Which factor is most important when determining log retention periods?
Select an answer first - 30
Which component of a SIEM is responsible for parsing raw log data into a normalized format?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.