Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 4Objective 3

Introduction to SIEM and SIEM Architecture SCE Practice Questions (Page 2)

Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
9concepts

Questions 6–10

  1. 6application · medium

    A company has a SIEM that receives logs from firewalls, Windows endpoints, and a custom in-house application. The application logs are in a key=value format, while the firewall logs are in syslog format. Analysts are struggling to write queries because field names differ across sources. What should the SIEM administrator do to address this?

    Select an answer first
  2. 7application · medium

    A SOC team is deploying a SIEM and needs to ingest logs from multiple remote offices. Each office has a different type of firewall and server. The team wants to ensure that logs are received reliably and converted into a standard format before being sent to the central correlation engine. Which SIEM component should be placed at each office?

    Select an answer first
  3. 8application · medium

    A SOC analyst wants to reduce alert fatigue by grouping alerts that originate from the same attack campaign. The SIEM has alerts from multiple rules that share a common indicator, such as the same source IP. What should the analyst configure to group these alerts?

    Select an answer first
  4. 9expert · hard

    A security team is using their SIEM for both real-time threat detection and monthly compliance reporting. The compliance report requires specific metrics that are not currently captured by any correlation rule. The team wants to generate the report without affecting real-time detection performance. What should they do?

    Select an answer first
  5. 10application · medium

    After a security incident, a company needs to determine the exact sequence of events that led to the breach. The SIEM has logs from the firewall, endpoint, and authentication systems. Which SIEM use case should the analyst apply to reconstruct the timeline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.