
EC-CouncilNetwork Defense Essentials
Domain 3Objective 5
SIEM, UBA/UEBA, and Endpoint Security Solutions NDE Practice Questions (Page 12)
Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.
59questions here
12free pages
10concepts
Questions 56–59
- 56
A security manager is evaluating SIEM solutions and wants to ensure the chosen product can collect logs from cloud services, on-premises servers, and network devices. Which SIEM component is most critical for this requirement?
Select an answer first - 57
A company's SIEM receives logs from firewalls, Windows event logs, and Linux syslog in different formats. The security team wants to detect a multi-stage attack where an attacker first performs a port scan, then exploits a web vulnerability, and later uses the same source IP to attempt lateral movement. Which SIEM capability is most directly required to make these events meaningful for detection?
Select an answer first - 58
What capability distinguishes EDR from traditional antivirus?
Select an answer first - 59
A UEBA system flags a service account that authenticates from a new IP address and accesses a database it has never accessed before. The security team is unsure whether this is a true positive because the account is used by an application that was recently updated. What should the team do?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to NDE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.