Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 6Objective 2

SIEM and SOAR CSE Practice Questions (Page 1)

Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.

42questions here
9free pages
7concepts

Questions 1–5

  1. 1foundation · easy

    Which method is commonly used by a SIEM to collect logs from cloud-based services?

    Select an answer first
  2. 2foundation · easy

    Why does a SIEM normalize log data from different sources?

    Select an answer first
  3. 3foundation · easy

    What is a key benefit of integrating SIEM with SOAR?

    Select an answer first
  4. 4expert · hard

    During an incident, the response team needs to contain a compromised server. The server is running critical business applications, and taking it offline will cause significant downtime. The team has a SOAR platform that can isolate the server from the network. What is the best course of action?

    Select an answer first
  5. 5application · medium

    A SIEM detects a potential ransomware outbreak and creates an alert. The security team wants the alert to automatically trigger containment actions, such as isolating affected endpoints, without waiting for a human analyst. Which integration capability is required?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.