
EC-CouncilCertified SOC Analyst
Domain 3Objective 2
SIEM Deployment and Architecture CSA Practice Questions (Page 7)
Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.
43questions here
9free pages
9concepts
Questions 31–35
- 31
A SOC is experiencing a high number of false positives from a correlation rule that alerts on 'multiple failed logins followed by a successful login.' The rule is triggered by legitimate users who mistype their passwords. The SOC wants to reduce false positives while still detecting brute-force attacks. Which adjustment is most effective?
Select an answer first - 32
What is the role of a correlation rule in a SIEM?
Select an answer first - 33
A SIEM is experiencing slow search performance and delayed alert processing as log volume has tripled. The storage tier is nearly full, and the correlation engine is CPU-bound. Which combination of actions would most effectively address the performance degradation?
Select an answer first - 34
A company runs a mix of on-premises Windows servers and cloud-based SaaS applications. The SOC needs to ingest authentication logs from both sources into a central SIEM. The Windows servers are in a DMZ with no direct internet access, and the SaaS provider offers a REST API for log export. Which collection method should be used for each source?
Select an answer first - 35
Which log collection method is most appropriate for a network device that only supports sending syslog messages over UDP port 514?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.