
EC-CouncilNetwork Defense Essentials
Domain 3Objective 5
SIEM, UBA/UEBA, and Endpoint Security Solutions NDE Practice Questions (Page 8)
Part of the Technical Security Controls domain, which makes up ~16% of our current practice bank.
59questions here
12free pages
10concepts
Questions 36–40
- 36
Which of the following is a core component of a SIEM system?
Select an answer first - 37
A security analyst notices that a user account has been downloading an unusually large volume of data from a file server every night for the past week. The user's role is in marketing and has never accessed this server before. The UEBA system flags this as anomalous. What is the most appropriate next step for the analyst?
Select an answer first - 38
A multinational company must comply with data residency regulations that require security logs to be stored within the country where the data originates. The company currently uses a single SIEM instance in a central data center. What is the best approach to meet this requirement?
Select an answer first - 39
A UEBA system is deployed in an organization where employees work in shifts and some users legitimately access systems at odd hours. The security team is concerned about false positives. What is the best way to configure the UEBA to reduce false positives while still detecting genuine anomalies?
Select an answer first - 40
A security analyst needs to investigate a suspicious PowerShell command that executed on a laptop two days ago. The analyst wants to see the full command line, the parent process, and any files created by that process. Which endpoint security capability should the analyst use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.