Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 3Objective 2

SIEM Deployment and Architecture CSA Practice Questions (Page 4)

Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.

43questions here
9free pages
9concepts

Questions 16–20

  1. 16application · medium

    A SOC wants to detect a potential data exfiltration where a user uploads a large file to a cloud storage service. The SIEM has logs from the proxy, endpoint, and data loss prevention (DLP) system. Which correlation rule would best detect this?

    Select an answer first
  2. 17application · medium

    A mid-sized company is deploying a SIEM and has a limited IT staff. They want to avoid managing physical hardware and need to scale quickly during peak periods. However, they have a regulatory requirement that log data must remain within the country's borders. Which deployment model best meets these needs?

    Select an answer first
  3. 18application · medium

    A company uses a SIEM and wants to improve detection of known malicious IP addresses and domains. They have a subscription to a commercial threat intelligence feed. Which integration approach is most effective?

    Select an answer first
  4. 19foundation · easy

    How does a SIEM typically integrate with an IDS/IPS to enhance detection?

    Select an answer first
  5. 20foundation · easy

    What is the primary purpose of log normalization in a SIEM?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.