Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 4Objective 4

SIEM Deployment Models and Data Sources SCE Practice Questions (Page 1)

Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
4concepts

Questions 1–5

  1. 1expert · hard

    A multinational company has an on-premises SIEM that is reaching capacity. They are planning to migrate to a cloud-based SIEM. The security team is concerned about the cost of data transfer and the need to retain logs for 5 years. They also have a hybrid network with some on-premises and some cloud workloads. Which approach best balances cost and compliance?

    Select an answer first
  2. 2application · medium

    A startup with a small SOC team wants to deploy a SIEM but has no dedicated IT staff to maintain servers. They expect log volume to grow unpredictably as they add new services. They also need to retain logs for at least one year for compliance. Which deployment model is most appropriate?

    Select an answer first
  3. 3expert · hard

    A company has a SIEM that ingests firewall logs and EDR alerts. The SIEM generates an alert when a firewall log shows a connection to a known malicious IP and an EDR alert on the same host. The SOC is experiencing a high false-positive rate because the EDR alert is often a generic 'suspicious behavior' that is not related to the network connection. How should the SOC refine the correlation rule?

    Select an answer first
  4. 4expert · hard

    A SIEM is receiving logs from a network device that uses a proprietary log format. The SIEM's default parser does not recognize the format, and the logs are being stored as raw text without being normalized. The SOC wants to search for a specific event type. What is the most efficient way to make these logs searchable?

    Select an answer first
  5. 5foundation · easy

    How does a SIEM typically integrate with an EDR solution to improve detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.