Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 5Objective 2

Event Correlation Concepts and Techniques DFE Practice Questions (Page 2)

Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.

41questions here
9free pages
5concepts

Questions 6–10

  1. 6expert · hard

    A large organization is experiencing a high volume of SIEM alerts, many of which are false positives. The security team wants to improve detection accuracy without increasing staffing. They are considering two approaches: (1) fine-tuning existing rule-based correlation rules, and (2) implementing a machine learning-based anomaly detection module. Which approach should they choose to best address the false positive problem while maintaining detection of known attack patterns?

    Select an answer first
  2. 7application · medium

    A security analyst is correlating events from multiple servers and notices that the same user account shows a successful login on two different servers at the exact same second. The analyst suspects a time synchronization issue. What is the best way to confirm this?

    Select an answer first
  3. 8foundation · easy

    A security analyst wants to detect unusual network traffic that deviates from the organization's normal baseline. Which correlation technique is most appropriate?

    Select an answer first
  4. 9foundation · easy

    In the event correlation process, what is the purpose of the normalization step?

    Select an answer first
  5. 10application · medium

    A security operations center (SOC) receives thousands of alerts daily from multiple sources. The team wants to reduce the number of false positives while still detecting novel attacks that do not match known signatures. Which correlation technique should the SOC implement to best address this requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.