
EC-CouncilNetwork Defense Essentials
Domain 3Objective 5
SIEM, UBA/UEBA, and Endpoint Security Solutions NDE Practice Questions (Page 1)
Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.
59questions here
12free pages
10concepts
Questions 1–5
- 1
What is the primary purpose of a Security Information and Event Management (SIEM) system?
Select an answer first - 2
A system administrator notices that a service account is logging in from a new location and at unusual times, but the account has a history of being used by automated scripts. The UEBA system has not raised an alert. What is the most likely reason for the lack of alert?
Select an answer first - 3
A company has a mix of Windows and Linux endpoints. The security team wants to deploy an EDR solution that provides centralized management, automated response, and supports both operating systems. They also want to minimize the number of vendors. What should they consider?
Select an answer first - 4
A security analyst is investigating a suspicious process on an endpoint. The EDR console shows the process has been making outbound network connections and modifying registry keys. The analyst wants to understand the full scope of the attack. Which EDR feature is most useful for this investigation?
Select an answer first - 5
During a ransomware outbreak, an EDR solution detects the encryption process on a workstation and automatically isolates the endpoint from the network. What is the primary benefit of this automated response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.