
EC-CouncilCloud Security Essentials
Domain 6Objective 2
SIEM and SOAR CSE Practice Questions (Page 2)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
42questions here
9free pages
7concepts
Questions 6–10
- 6
A SOAR playbook is triggered by a SIEM alert for a possible compromised account. The playbook is supposed to (1) disable the account, (2) reset the password, and (3) notify the user. However, the playbook fails at step 2 because the password reset API is temporarily unavailable. What is the best practice for handling this failure?
Select an answer first - 7
Which component is a typical part of a SIEM architecture?
Select an answer first - 8
In the incident response process, which phase involves identifying whether an alert is a real incident?
Select an answer first - 9
A security operations center (SOC) receives hundreds of alerts daily. Analysts spend most of their time on repetitive tasks like checking IP reputation and opening tickets. The SOC manager wants to reduce this workload while keeping human oversight for critical decisions. Which approach is most effective?
Select an answer first - 10
How does a SOAR playbook typically execute an automated response action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.