
EC-CouncilCertified Security Specialist
Domain 1Objective 5
Technical Controls (firewalls, IDS/IPS, VPNs, SIEM) ECSS Practice Questions (Page 10)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
51questions here
11free pages
14concepts
Questions 46–50
- 46
An organization needs to detect a brute-force attack that involves multiple failed logins across several servers within a short time window. They have a SIEM that collects authentication logs from all servers. Which SIEM feature should they configure to identify this pattern?
Select an answer first - 47
A sales team uses personal laptops to connect to the corporate network from home. The company wants a VPN that works without requiring pre-installed client software and provides secure access through a web browser. Which VPN technology should be chosen?
Select an answer first - 48
How does a SIEM system help security analysts detect threats?
Select an answer first - 49
Which IDS/IPS detection method relies on a database of known attack patterns?
Select an answer first - 50
What is the purpose of ordering firewall rules from specific to general?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.