
EC-CouncilSOC Essentials
Domain 4Objective 4
SIEM Deployment Models and Data Sources SCE Practice Questions (Page 2)
Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
4concepts
Questions 6–10
- 6
A SOC wants to reduce false positives in SIEM alerts by adding context about whether an endpoint has a known vulnerability. Which integration would provide this context directly to the SIEM?
Select an answer first - 7
A SOC wants to detect a multi-stage attack that starts with a phishing email, then uses a malicious script on an endpoint, and finally exfiltrates data over the network. Which SIEM integration is most important to see the full attack chain?
Select an answer first - 8
A SOC is investigating a potential data breach. The SIEM has logs from the firewall, EDR, and authentication server, but the analyst cannot determine whether a specific file was accessed on a file server. Which additional data source would fill this gap?
Select an answer first - 9
A SIEM is receiving logs from a network IDS that generates alerts in Suricata EVE JSON format and from a Windows server that generates Event ID 4625 (failed logon) logs. The analyst wants to correlate IDS alerts with failed logons from the same source IP. What must the SIEM do first to enable this correlation?
Select an answer first - 10
A SOC wants to detect malware command-and-control (C2) traffic by correlating domain name lookups with network connections. Which two data sources are essential for this detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.