
EC-CouncilCertified SOC Analyst
Domain 3Objective 2
SIEM Deployment and Architecture CSA Practice Questions (Page 3)
Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.
43questions here
9free pages
9concepts
Questions 11–15
- 11
A SIEM is receiving logs from multiple vendors, each with a different timestamp format and field names. The SOC wants to correlate events across these sources. What must be done to enable effective correlation?
Select an answer first - 12
Which strategy is used to ensure high availability of a SIEM by deploying multiple instances of critical components?
Select an answer first - 13
A SOC manager is designing a high-availability SIEM architecture. The SIEM must remain operational if a single component fails, and the team has a limited budget. The current architecture uses a single collector, a single correlation engine, and a single storage node. Which design provides the best balance of availability and cost?
Select an answer first - 14
A SOC's SIEM is missing events during peak hours because the collector cannot keep up with the incoming log rate. The team has budget constraints and cannot add more collectors. The log sources include high-volume firewall logs and lower-volume authentication logs. Which optimization would best reduce the collector's load without losing critical security visibility?
Select an answer first - 15
During parsing of a raw log entry, which of the following is typically extracted as a field for analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.