
EC-CouncilDigital Forensics Essentials
Domain 5Objective 2
Event Correlation Concepts and Techniques DFE Practice Questions (Page 1)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
41questions here
9free pages
5concepts
Questions 1–5
- 1
A small company has a SIEM but limited staffing. They want to detect known attack patterns with minimal false positives and without requiring constant tuning. Which correlation technique is most appropriate for this environment?
Select an answer first - 2
A small company wants to improve its ability to detect web attacks by correlating logs from its web server, firewall, and authentication system. The company has a limited budget and no dedicated security staff. Which tool would best meet their needs for automated event correlation?
Select an answer first - 3
A forensic examiner is investigating a web attack and has collected logs from the web server, database server, and a network intrusion detection system (IDS). The examiner wants to determine the exact sequence of events that led to data exfiltration. What is the primary purpose of correlating these events?
Select an answer first - 4
An analyst is correlating events from a web server and an authentication server to investigate a possible account takeover. The authentication server logs show a successful login from a new device, and the web server logs show a subsequent change to the user's email address. The analyst wants to confirm that these events are related. Which additional data would be most useful for correlation?
Select an answer first - 5
A security analyst is investigating a web attack that involved multiple stages: a port scan, a vulnerability exploit, and data exfiltration. The analyst has logs from the firewall, web server, and DNS server. The logs are in different formats and timezones. What is the most important first step in correlating these events?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.