Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 6Objective 2

SIEM and SOAR CSE Practice Questions (Page 3)

Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.

42questions here
9free pages
7concepts

Questions 11–15

  1. 11application · medium

    A security analyst notices that the SIEM generates an alert every time a user fails to log in twice within five minutes. The organization has many users who mistype passwords, causing a high volume of false positives. What is the best way to reduce the noise while still detecting brute-force attacks?

    Select an answer first
  2. 12application · medium

    During an incident, the incident response team needs to quickly determine which systems were affected by a malware infection. They have a SIEM that collects logs from all endpoints and network devices. Which SIEM capability is most directly useful for this task?

    Select an answer first
  3. 13application · medium

    An organization's SIEM is configured to alert on a single failed login, but the security team wants to detect a brute-force attack that involves multiple failed logins from the same source IP across different user accounts. What is the most effective way to configure the SIEM?

    Select an answer first
  4. 14expert · hard

    A SOC wants to automate response to a high-volume, low-severity alert type. The SOAR playbook will automatically quarantine the affected endpoint and block the associated IP. However, the security manager is concerned about false positives disrupting business operations. Which playbook design best balances automation and risk?

    Select an answer first
  5. 15application · medium

    During an incident, the security team needs to determine which systems were accessed by a compromised account. The SIEM has logs from authentication, network, and endpoint sources. What is the most efficient way to gather this information?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.