
EC-CouncilCertified SOC Analyst
Domain 3Objective 2
SIEM Deployment and Architecture CSA Practice Questions (Page 6)
Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.
43questions here
9free pages
9concepts
Questions 26–30
- 26
A SIEM is receiving logs from different vendors in various formats. The analyst wants to create a correlation rule that uses the source IP address from both Windows Event Logs and Linux syslog. What must be done to ensure the rule works correctly?
Select an answer first - 27
Which approach is commonly used to scale a SIEM to handle increasing log volumes?
Select an answer first - 28
Why is it important to regularly update correlation rules in a SIEM?
Select an answer first - 29
A SIEM administrator is planning for a major expansion of log sources. The current SIEM is on-premises and uses a single server for collection, parsing, correlation, and storage. The administrator expects the data volume to triple. The budget is limited, and the administrator wants to minimize disruption. Which approach is most effective?
Select an answer first - 30
A SOC team has noticed that a new application server is not sending logs to the SIEM. The server was added to the network last week. Which routine administrative task should be performed to resolve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.