
EC-CouncilSOC Essentials
Domain 5Objective 4
Logging Best Practices SCE Practice Questions (Page 5)
Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
6concepts
Questions 21–25
- 21
Which measure is most effective for detecting tampering with log files?
Select an answer first - 22
A company's SOC team is overwhelmed by the volume of logs from firewalls and endpoints. They want to focus on meaningful security events without missing critical incidents. What should they implement first?
Select an answer first - 23
A security analyst notices that log entries from a critical database server are missing the user ID and source IP fields, making it impossible to correlate an alert with a specific account. The analyst needs to ensure future logs contain this context. What should the analyst do?
Select an answer first - 24
A SOC team is configuring alerts for a web application. They want to detect a potential SQL injection attack. The application logs include the full URL and query parameters. Which alert rule would be most effective?
Select an answer first - 25
A small business has a compliance requirement to keep authentication logs for one year. They also need to troubleshoot a recent incident that occurred three months ago. The logs are currently stored on the local disk of each server. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.