
EC-CouncilSOC Essentials
Domain 4Objective 3
Introduction to SIEM and SIEM Architecture SCE Practice Questions (Page 10)
Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 46–50
- 46
When a SIEM generates an alert based on a set of predefined rules, what is this process called?
Select an answer first - 47
A SIEM is ingesting logs from a custom application that outputs timestamps in a non-standard format (e.g., '2024-03-01 14:30:22.123456'). The correlation engine is not matching events from this application with events from other sources because the timestamps are not being converted to the SIEM's standard time format. What should the administrator do to fix this?
Select an answer first - 48
Which of the following is a core function of a SIEM system?
Select an answer first - 49
A small company has separate logs from its firewall, antivirus, and web server. The security manager wants a single view that can show a potential attack that spans all three systems. What is the primary reason to deploy a SIEM in this situation?
Select an answer first - 50
Which of the following best describes the role of SIEM in a security operations center (SOC)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SCE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.