
EC-CouncilCertified DevSecOps Engineer
Domain 6Objective 4
Monitoring and Logging ECDE Practice Questions (Page 4)
Part of the Operate and Monitor Stage domain, which makes up ~21% of our current practice bank.
43questions here
9free pages
9concepts
Questions 16–20
- 16
What is a recommended practice for protecting log data?
Select an answer first - 17
A security analyst is investigating a potential insider threat. The user has legitimate access to sensitive data. Which monitoring approach would provide the most useful evidence?
Select an answer first - 18
A security operations team is investigating a potential account takeover. They have access to authentication logs, network logs, and endpoint logs. Which combination of data would provide the strongest evidence of the attack?
Select an answer first - 19
A SOC analyst notices that a legitimate user's account is generating a high number of failed login attempts followed by a successful login from a different geographic location. The SIEM has a rule for impossible travel, but it has not fired. What is the most likely reason and what should be done?
Select an answer first - 20
A company's security policy requires that logs be immutable and cannot be altered by attackers who compromise the application. They use a centralized logging platform. Which configuration is most important to meet this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.