
EC-CouncilCloud Security Essentials
Domain 6Objective 2
SIEM and SOAR CSE Practice Questions (Page 6)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
42questions here
9free pages
7concepts
Questions 26–30
- 26
A security operations team wants to reduce the time spent on phishing alerts. They plan to use SOAR to automatically quarantine a suspicious email and block the sender, but they are concerned about acting without human review. What is the most appropriate approach?
Select an answer first - 27
A security team wants to automate the response to low-severity alerts so analysts can focus on critical incidents. They have a SIEM that generates alerts and a ticketing system. What should they implement to achieve this?
Select an answer first - 28
During an incident, the response team needs to collect forensic evidence from a compromised server. They want to ensure the evidence is preserved and documented for potential legal action. Which step in the incident response workflow is most critical at this point?
Select an answer first - 29
When a SIEM generates an alert, what does that alert typically indicate?
Select an answer first - 30
A small business wants to implement a SIEM to meet a compliance requirement that mandates log retention and review. They have limited budget and IT staff. Which deployment model is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.