
EC-CouncilCertified Security Specialist
Domain 1Objective 5
Technical Controls (firewalls, IDS/IPS, VPNs, SIEM) ECSS Practice Questions (Page 5)
Part of the Network Defense Fundamentals and Controls domain, which makes up ~21% of our current practice bank.
51questions here
11free pages
14concepts
Questions 21–25
- 21
Which VPN protocol is commonly used for secure remote access and operates at the application layer, often leveraging web browsers?
Select an answer first - 22
A security team wants to reduce the time to detect a multi-stage attack that spans multiple servers. They plan to collect logs from firewalls, servers, and endpoints into a central system that can identify related events across different sources. Which SIEM function directly enables this capability?
Select an answer first - 23
In a screened subnet architecture, what is the purpose of placing a DMZ between two firewalls?
Select an answer first - 24
A SOC team is overwhelmed by the volume of alerts from their SIEM. Most alerts are false positives, and critical alerts are being missed. The team wants to reduce noise while ensuring that genuine threats are not overlooked. Which approach should be taken?
Select an answer first - 25
During incident response, how does a SIEM assist security analysts?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.