
EC-CouncilSOC Essentials
Domain 5Objective 3
Local vs. Centralized Log Management SCE Practice Questions (Page 9)
Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
9concepts
Questions 41–45
- 41
In centralized log management, how are logs from different sources handled?
Select an answer first - 42
A company is planning to centralize logs from 2,000 servers to a single SIEM. The security team is concerned about the SIEM becoming a bottleneck and about the cost of storage. Which measure would best address these concerns while still gaining the benefits of centralization?
Select an answer first - 43
In which scenario is local log management most appropriate?
Select an answer first - 44
A security analyst is investigating a potential data exfiltration. The analyst needs to see if a user logged into a server, accessed a file share, and then transferred data to an external IP. The logs are currently stored locally on each system. What is the most efficient way to perform this investigation?
Select an answer first - 45
A startup with 10 employees and a single office is considering moving from local to centralized log management. They have no compliance requirements and their main concern is keeping costs low. What should they consider?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.