
EC-CouncilCloud Security Essentials
Domain 6Objective 2
SIEM and SOAR CSE Practice Questions (Page 8)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
42questions here
9free pages
7concepts
Questions 36–40
- 36
A SIEM is ingesting logs from a legacy application that uses a non-standard timestamp format (e.g., 'MM/DD/YYYY HH:MM:SS AM/PM') and does not include timezone information. The SIEM's default parser expects UTC in ISO 8601 format. As a result, events are being timestamped with the current UTC time at ingestion, not the actual event time. What is the best way to fix this?
Select an answer first - 37
A SIEM generates thousands of low-priority alerts per day, and the security team is overwhelmed. They want to reduce noise while still detecting multi-step attacks that span different systems. Which approach best achieves this?
Select an answer first - 38
A company's SIEM is receiving logs from cloud services, on-premises servers, and SaaS applications. The security team notices that the same user activity appears with different timestamps and user ID formats across sources. This makes it difficult to correlate a single user's actions. What is the best way to address this?
Select an answer first - 39
A small company wants to deploy a SIEM to monitor its cloud infrastructure. They have limited staff and need to see security events from multiple cloud services in one place. What is the primary benefit they should expect from the SIEM?
Select an answer first - 40
What is the role of correlation rules in a SIEM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.