
EC-CouncilCloud Security Essentials
Domain 6Objective 2
SIEM and SOAR CSE Practice Questions (Page 5)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
42questions here
9free pages
7concepts
Questions 21–25
- 21
What is the primary goal of Security Orchestration, Automation, and Response (SOAR)?
Select an answer first - 22
A SIEM correlation rule detects a potential data exfiltration event when a user uploads more than 1 GB of data to an external cloud storage service within an hour. The rule generates many alerts for legitimate users who regularly back up data. The security team wants to reduce false positives while still detecting unusual exfiltration. What is the best approach?
Select an answer first - 23
A SOAR playbook is designed to respond to a malware alert. The first step enriches the alert with threat intelligence, the second step isolates the affected host, and the third step creates a ticket. The playbook fails at the second step because the host isolation API returns an error. What should the playbook do?
Select an answer first - 24
A company has a SIEM that generates a high volume of low-fidelity alerts. They are deploying a SOAR platform to automate response. The security team is concerned that the SOAR playbooks might act on false positives and cause disruption. What is the most effective way to balance automation with safety?
Select an answer first - 25
A company's SIEM ingests logs from cloud access security broker (CASB) and identity provider (IdP) sources. The CASB logs use a field named 'user' with the format 'jdoe', while the IdP logs use 'userPrincipalName' with the format 'jdoe@company.com'. The security team wants to correlate a single user's activity across both sources. They have limited SIEM processing capacity and cannot afford to store duplicate data. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.