
EC-CouncilSOC Essentials
Domain 5Objective 5
Logging and Log Management Tools SCE Practice Questions (Page 3)
Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 11–15
- 11
Why is JSON a popular format for modern log management systems?
Select an answer first - 12
A security team is choosing between two log management tools: Tool A is a SIEM with built-in correlation rules but requires agents on every server. Tool B is a log aggregator that accepts syslog and has a query interface but no correlation engine. The team has limited administrative time and needs to detect attacks across servers. Which tool is more appropriate?
Select an answer first - 13
An organization is investigating a data breach. They have logs from the firewall, web server, and database. Which log source is most likely to reveal the exact data that was exfiltrated?
Select an answer first - 14
An analyst is investigating a potential data exfiltration. The firewall logs show a large outbound transfer to an external IP. The proxy logs show a user downloading a file from a file-sharing site. The authentication logs show the user logged in at the same time. Which correlation would provide the strongest evidence that the user is responsible?
Select an answer first - 15
Which of the following is an example of using log analysis to detect a security incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.