
EC-CouncilCertified SOC Analyst
Domain 4Objective 2
Use Case and Correlation Rule Development CSA Practice Questions (Page 6)
Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.
30questions here
6free pages
8concepts
Questions 26–30
- 26
A SOC is building a use case to detect 'insider threat: unauthorized access to sensitive files'. The organization uses Windows file servers and Active Directory. Which log sources and fields are necessary to support this use case?
Select an answer first - 27
Which operator would you use in a correlation rule to trigger when the count of failed login events is greater than or equal to 5?
Select an answer first - 28
Which data field is essential for a use case that detects multiple failed login attempts to a domain controller?
Select an answer first - 29
Which component is typically included in the structure of a well-defined security use case?
Select an answer first - 30
A SOC is creating a use case for 'malicious PowerShell execution'. The analyst must document the use case for future reference. Which set of documentation elements is most complete for a SOC use case?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.