
EC-CouncilNetwork Defense Essentials
Domain 3Objective 5
SIEM, UBA/UEBA, and Endpoint Security Solutions NDE Practice Questions (Page 2)
Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.
59questions here
12free pages
10concepts
Questions 6–10
- 6
A company is deploying EDR agents to 5,000 endpoints. The security team wants to ensure that the rollout does not disrupt business operations and that the agents are properly configured. What is the best practice for this deployment?
Select an answer first - 7
Which of the following is a typical use case for a SIEM system?
Select an answer first - 8
Which of the following is a best practice for managing endpoint security in an enterprise?
Select an answer first - 9
An organization needs to demonstrate to an auditor that all authentication failures across servers and network devices are being reviewed. The security team currently collects logs in a SIEM. What should the team configure to satisfy this requirement?
Select an answer first - 10
A UEBA system is generating too many alerts for a group of users who frequently travel and access the network from different countries. The security team wants to reduce noise without missing real threats. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.