Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 3Objective 1

Log Management and Correlation CSA Practice Questions (Page 8)

Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
10concepts

Questions 36–40

  1. 36foundation · easy

    Which log type is primarily used to track user activities and system events for security auditing?

    Select an answer first
  2. 37foundation · easy

    Which of the following is an example of a network device log source?

    Select an answer first
  3. 38application · medium

    A company is designing a log management program. They want to ensure logs are available for incident investigation and meet compliance requirements. Which practice is essential?

    Select an answer first
  4. 39application · medium

    A SOC wants to detect a brute-force attack on a VPN gateway. The SIEM receives authentication logs from the VPN. Which correlation rule technique is most appropriate?

    Select an answer first
  5. 40application · medium

    A SOC is evaluating a SIEM solution. They need real-time correlation of events from multiple sources and the ability to enrich events with threat intelligence. Which SIEM capability is most important for this requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.