
EC-CouncilCertified SOC Analyst
Domain 3Objective 1
Log Management and Correlation CSA Practice Questions (Page 7)
Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
10concepts
Questions 31–35
- 31
A SOC analyst is reviewing a correlation rule that triggers when 'a user logs in from a new location and then accesses a sensitive file.' The rule is meant to detect account compromise. Which correlation concept does this rule primarily use?
Select an answer first - 32
What is a common challenge in log correlation that can lead to alert fatigue?
Select an answer first - 33
A SOC analyst wants to detect malware propagation within the network. The SIEM collects logs from endpoints, firewalls, and DNS servers. Which correlation use case would best detect this?
Select an answer first - 34
A SOC has a correlation rule that detects multiple failed logins followed by a successful login. The rule is generating many alerts for legitimate users who simply forgot their passwords. The team wants to reduce false positives without missing real brute-force attacks. Which adjustment is most appropriate?
Select an answer first - 35
A multinational company has offices in three regions and wants to centralize logs into a single SIEM. The network links between regions have limited bandwidth, and the SIEM is in a central data center. The team needs to ensure logs are collected without overwhelming the WAN links. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.