
EC-CouncilCloud Security Essentials
Domain 6Objective 2
SIEM and SOAR CSE Practice Questions (Page 1)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
42questions here
9free pages
7concepts
Questions 1–5
- 1
Which method is commonly used by a SIEM to collect logs from cloud-based services?
Select an answer first - 2
Why does a SIEM normalize log data from different sources?
Select an answer first - 3
What is a key benefit of integrating SIEM with SOAR?
Select an answer first - 4
During an incident, the response team needs to contain a compromised server. The server is running critical business applications, and taking it offline will cause significant downtime. The team has a SOAR platform that can isolate the server from the network. What is the best course of action?
Select an answer first - 5
A SIEM detects a potential ransomware outbreak and creates an alert. The security team wants the alert to automatically trigger containment actions, such as isolating affected endpoints, without waiting for a human analyst. Which integration capability is required?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.