
EC-CouncilCertified Security Specialist
Domain 1Objective 5
Technical Controls (firewalls, IDS/IPS, VPNs, SIEM) ECSS Practice Questions (Page 3)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
51questions here
11free pages
14concepts
Questions 11–15
- 11
In a SIEM, what is the purpose of the correlation engine?
Select an answer first - 12
What is the primary function of an Intrusion Detection System (IDS)?
Select an answer first - 13
A security analyst is evaluating an IDS that has a high false-positive rate because it flags normal administrative activity as suspicious. The analyst wants to reduce false positives while still detecting novel attacks that do not match known signatures. Which approach best balances these goals?
Select an answer first - 14
What is a primary advantage of anomaly-based detection over signature-based detection?
Select an answer first - 15
A network administrator needs to block traffic based on the application protocol, such as allowing HTTP but not peer-to-peer file sharing, even if the traffic uses the same port. Which type of firewall is required for this level of inspection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.