
EC-CouncilCertified SOC Analyst
Domain 4Objective 2
Use Case and Correlation Rule Development CSA Practice Questions (Page 5)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
30questions here
6free pages
8concepts
Questions 21–25
- 21
A SOC team is developing a use case to detect data exfiltration via DNS tunneling. The team has access to DNS server logs, firewall logs, and proxy logs. Which combination of log sources and fields is most essential for this use case?
Select an answer first - 22
A correlation rule for 'privileged account misuse' has been in production for a year. The rule triggers on any admin login outside business hours. Recently, the SOC has seen a surge in false positives because a new on-call rotation requires admins to work late. The rule also missed a real incident where an admin account was used from a compromised workstation during business hours. The SOC lead must decide how to update the rule. Which action best balances false positives and detection?
Select an answer first - 23
A SOC analyst has written a correlation rule to detect 'data staging' by alerting on a large number of file copies to a single directory. The analyst has a test environment that mirrors production. Which validation strategy is most effective to ensure the rule works before production deployment?
Select an answer first - 24
A correlation rule that detects 'multiple failed logins' has been in production for six months. The SOC has observed that the rule no longer fires for a new brute-force tool that spreads attempts across many source IPs. What is the most appropriate lifecycle action?
Select an answer first - 25
A newly deployed correlation rule for 'multiple failed logins followed by success' is generating a high volume of alerts during business hours. The analyst reviews the alerts and finds that most are legitimate users who mistyped their password a few times before succeeding. Which tuning adjustment would most effectively reduce false positives while preserving detection of actual brute-force attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.