Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 4Objective 2

Use Case and Correlation Rule Development CSA Practice Questions (Page 4)

Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.

30questions here
6free pages
8concepts

Questions 16–20

  1. 16expert · hard

    A SOC is developing a use case to detect 'internal reconnaissance via port scans'. The organization has both NetFlow and full packet capture (PCAP) available. The analyst must decide which data source to use for the correlation rule. Which consideration is most important?

    Select an answer first
  2. 17foundation · easy

    Which data source is most relevant for a use case that detects unauthorized access to a corporate web application?

    Select an answer first
  3. 18expert · hard

    A SOC analyst is building a correlation rule to detect 'a user downloading a large file and then sending it via email'. The organization has proxy logs and email logs. Which correlation logic is most effective?

    Select an answer first
  4. 19foundation · easy

    What is a common technique to reduce false positives in a correlation rule that detects multiple failed logins?

    Select an answer first
  5. 20foundation · easy

    Which element is typically included in a use case document?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.