
EC-CouncilCertified SOC Analyst
Domain 3Objective 2
SIEM Deployment and Architecture CSA Practice Questions (Page 4)
Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.
43questions here
9free pages
9concepts
Questions 16–20
- 16
A SOC wants to detect a potential data exfiltration where a user uploads a large file to a cloud storage service. The SIEM has logs from the proxy, endpoint, and data loss prevention (DLP) system. Which correlation rule would best detect this?
Select an answer first - 17
A mid-sized company is deploying a SIEM and has a limited IT staff. They want to avoid managing physical hardware and need to scale quickly during peak periods. However, they have a regulatory requirement that log data must remain within the country's borders. Which deployment model best meets these needs?
Select an answer first - 18
A company uses a SIEM and wants to improve detection of known malicious IP addresses and domains. They have a subscription to a commercial threat intelligence feed. Which integration approach is most effective?
Select an answer first - 19
How does a SIEM typically integrate with an IDS/IPS to enhance detection?
Select an answer first - 20
What is the primary purpose of log normalization in a SIEM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.