Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 5Objective 1

Events, Incidents, and Logs SCE Practice Questions (Page 7)

Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
5concepts

Questions 31–35

  1. 31expert · hard

    A company's SIEM receives logs from multiple sources, but the timestamps are inconsistent: some are in UTC, some in local time, and some have no timezone information. This is causing correlation errors. What is the most effective solution?

    Select an answer first
  2. 32expert · hard

    A company is required to retain logs for regulatory compliance. They currently store logs in a SIEM for 30 days and then delete them. The regulation requires 1 year of retention. The SIEM storage is expensive, and the company wants to minimize costs. Which approach is most appropriate?

    Select an answer first
  3. 33application · medium

    A company is setting up a central log management system. The security team wants to collect logs from a firewall, a Windows domain controller, and a custom web application. The web application outputs JSON logs, while the firewall and domain controller support syslog. Which approach best consolidates these logs for analysis?

    Select an answer first
  4. 34application · medium

    A company experiences a malware infection on a workstation. The SOC analyst needs to trace how the malware entered the network. Which combination of log sources would be most useful for this investigation?

    Select an answer first
  5. 35application · medium

    During an investigation, an analyst correlates a failed login event on a domain controller with a successful login event from the same account 10 minutes later, followed by a data exfiltration alert from the DLP system. Which statement best describes how these logs contribute to incident detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.