Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 3Objective 2

SIEM Deployment and Architecture CSA Practice Questions (Page 8)

Part of the Log Management and SIEM domain, which makes up ~13% of our current practice bank.

43questions here
9free pages
9concepts

Questions 36–40

  1. 36foundation · easy

    What is a common performance tuning technique to reduce the processing load on a SIEM?

    Select an answer first
  2. 37expert · hard

    A multinational company is deploying a SIEM and must comply with data residency regulations that require certain log data to remain within the country of origin. The company also wants to centralize security monitoring. Which deployment model is most appropriate?

    Select an answer first
  3. 38foundation · easy

    Which SIEM component transforms raw log entries into a structured format with consistent field names and values so that events from different sources can be compared?

    Select an answer first
  4. 39expert · hard

    A SIEM administrator is updating correlation rules to address a new threat. After deploying the rules, the SOC notices that some legitimate events are being flagged as malicious. What is the best practice to avoid this issue in the future?

    Select an answer first
  5. 40expert · hard

    A SOC manager is designing a SIEM architecture with high availability. The SIEM must be able to continue processing logs if one data center fails. The company has two data centers in different regions. Which architecture provides the best continuity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.