Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 6Objective 2

SIEM and SOAR CSE Practice Questions (Page 7)

Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.

42questions here
9free pages
7concepts

Questions 31–35

  1. 31foundation · easy

    In a SOAR platform, what is a playbook?

    Select an answer first
  2. 32expert · hard

    A SIEM correlation rule is designed to detect a potential brute-force attack by counting failed login attempts per source IP. The rule currently triggers an alert after 5 failed attempts within 10 minutes. The security team is overwhelmed by alerts from a few legitimate users who frequently mistype passwords. They want to reduce false positives without missing distributed brute-force attacks that use many different source IPs. What is the best approach?

    Select an answer first
  3. 33application · medium

    A company has both a SIEM and a SOAR platform. The SIEM detects a potential data exfiltration event and creates an alert. What is the most effective way for the SOAR platform to handle this alert?

    Select an answer first
  4. 34expert · hard

    A SIEM correlation rule is designed to detect a potential data exfiltration by alerting when a user uploads more than 100 MB of data to an external cloud storage service within 10 minutes. The rule is generating a high number of false positives because some users regularly upload large files as part of their job. The security team wants to reduce false positives without missing real exfiltration. Which approach is most effective?

    Select an answer first
  5. 35application · medium

    A company's SIEM receives firewall logs that record source IPs in dotted-decimal format and proxy logs that record them as integers. The security team wants to correlate a single source IP across both log types to detect a scanning campaign. What must be configured first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.