Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilNetwork Defense Essentials

Domain 3Objective 5

SIEM, UBA/UEBA, and Endpoint Security Solutions NDE Practice Questions (Page 10)

Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.

59questions here
12free pages
10concepts

Questions 46–50

  1. 46expert · hard

    A SIEM is receiving logs from multiple sources, but the security team is overwhelmed by false positives. They suspect that the correlation rules are too broad. The team wants to reduce false positives without missing real attacks. What is the most effective approach?

    Select an answer first
  2. 47application · medium

    An organization wants to ensure that only approved software can run on its point-of-sale terminals to prevent unauthorized applications. Which endpoint security technology is designed for this purpose?

    Select an answer first
  3. 48foundation · easy

    How can EDR provide automated response to a detected threat on an endpoint?

    Select an answer first
  4. 49foundation · easy

    What does 'normalization' mean in the context of SIEM data processing?

    Select an answer first
  5. 50expert · hard

    An organization wants to prevent employees from running unauthorized software on their workstations while also allowing IT-approved tools. They are considering application control. What is the most important factor for a successful implementation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.