Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 4Objective 2

Use Case and Correlation Rule Development CSA Practice Questions (Page 6)

Part of the Incident Detection and Triage domain, which makes up ~16% of our current practice bank.

30questions here
6free pages
8concepts

Questions 26–30

  1. 26application · medium

    A SOC is building a use case to detect 'insider threat: unauthorized access to sensitive files'. The organization uses Windows file servers and Active Directory. Which log sources and fields are necessary to support this use case?

    Select an answer first
  2. 27foundation · easy

    Which operator would you use in a correlation rule to trigger when the count of failed login events is greater than or equal to 5?

    Select an answer first
  3. 28foundation · easy

    Which data field is essential for a use case that detects multiple failed login attempts to a domain controller?

    Select an answer first
  4. 29foundation · easy

    Which component is typically included in the structure of a well-defined security use case?

    Select an answer first
  5. 30application · medium

    A SOC is creating a use case for 'malicious PowerShell execution'. The analyst must document the use case for future reference. Which set of documentation elements is most complete for a SOC use case?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.