Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 5Objective 2

Event Correlation Concepts and Techniques DFE Practice Questions (Page 6)

Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.

41questions here
9free pages
5concepts

Questions 26–30

  1. 26application · medium

    A company uses a SIEM platform to collect logs from firewalls, web servers, and authentication systems. The security team wants to detect a multi-stage attack where an attacker first scans the network, then exploits a web vulnerability, and finally uses stolen credentials. Which SIEM feature is most directly used to correlate these events?

    Select an answer first
  2. 27application · medium

    A forensic investigator is correlating events from a compromised web server and a database server. The web server logs are in UTC, while the database logs are in local time (UTC+5). The investigator notices that a SQL injection attempt in the web logs appears to occur after the database query in the database logs. What is the most likely issue, and what should the investigator do?

    Select an answer first
  3. 28application · medium

    A SIEM analyst is reviewing alerts generated by a correlation rule that flags any login followed by a file download within five minutes. The analyst notices that many alerts are triggered by normal user behavior. What is the most effective way to reduce these false positives?

    Select an answer first
  4. 29expert · hard

    During an investigation, an analyst is correlating events from a web server and an authentication server. The web server logs show a successful login followed by a privilege escalation, but the authentication server logs show no corresponding login event. The analyst suspects that the authentication server logs are incomplete. What is the best course of action?

    Select an answer first
  5. 30expert · hard

    A SOC is evaluating a SIEM that uses statistical correlation to detect anomalies. The SIEM flags a user who typically logs in from the US suddenly logging in from a foreign country. However, the user is on a legitimate business trip. The SOC wants to reduce such false positives without missing real account takeovers. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.