
EC-CouncilDigital Forensics Essentials
Domain 5Objective 2
Event Correlation Concepts and Techniques DFE Practice Questions (Page 7)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
41questions here
9free pages
5concepts
Questions 31–35
- 31
During an investigation, an analyst is correlating events from a web server and a firewall. The firewall logs show that a particular IP address was blocked, but the web server logs show a successful request from that same IP address at the same time. The analyst suspects a false positive in the firewall logs. What is the most appropriate next step?
Select an answer first - 32
A SOC team is evaluating SIEM solutions to improve event correlation for web attack detection. They have a high volume of logs and need to reduce false positives. Which SIEM feature is most important for this requirement?
Select an answer first - 33
A forensic investigator is correlating events from a web server and a database server to determine if a SQL injection attack led to data exfiltration. The web server logs show the attack at 10:00:00 UTC, but the database server logs show the corresponding query at 09:59:30 UTC. The investigator suspects a time synchronization issue. What is the most appropriate action to take?
Select an answer first - 34
A forensic investigator is examining a web attack that involved multiple steps: reconnaissance, exploitation, and data exfiltration. The investigator has logs from the web server, firewall, and DNS server. What is the primary purpose of correlating these logs?
Select an answer first - 35
An organization wants to detect brute-force attacks on its web application. The attack involves many failed login attempts from different IP addresses over a short period. Which correlation technique would be most effective in identifying this pattern?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.