
EC-CouncilCertified SOC Analyst
Domain 3Objective 1
Log Management and Correlation CSA Practice Questions (Page 9)
Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
10concepts
Questions 41–45
- 41
A SOC team is experiencing a high volume of alerts from a correlation rule that detects 'multiple failed logins followed by a successful login.' The rule is generating too many false positives because of a known application that retries authentication. The team wants to maintain detection of real brute-force attacks. What is the best approach?
Select an answer first - 42
A SOC team has deployed a correlation rule that triggers on 'multiple failed logins followed by a successful login.' The rule is generating too many false positives because legitimate users often forget their passwords. What is the best way to reduce false positives while still detecting brute force?
Select an answer first - 43
In the context of security operations, what is the primary purpose of log management?
Select an answer first - 44
Which best practice helps improve the accuracy of correlation rules and reduce false positives?
Select an answer first - 45
A SOC team has a correlation rule that triggers on '10 failed logins from the same source IP within 5 minutes.' The rule is generating many false positives because a NAT gateway causes many users to share the same public IP. The team wants to reduce false positives while still detecting brute force. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.