
EC-CouncilSOC Essentials
Domain 4Objective 4
SIEM Deployment Models and Data Sources SCE Practice Questions (Page 5)
Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
4concepts
Questions 21–25
- 21
A SOC wants to automatically block an IP address at the firewall when the SIEM detects a malicious scan. Which integration is required?
Select an answer first - 22
A SOC analyst is configuring a SIEM to detect unauthorized access attempts across the network. Which combination of data sources would provide the most comprehensive visibility for this use case?
Select an answer first - 23
Which of the following is a common data source category that a SIEM collects logs from?
Select an answer first - 24
A company is considering moving from an on-premises SIEM to a cloud-based SIEM. They have a highly regulated workload that requires low-latency access to logs for real-time alerting. Their internet connection is reliable but has a 50ms latency to the cloud region. The SOC is concerned about the impact on real-time detection. Which factor is most important to evaluate?
Select an answer first - 25
A SIEM is receiving logs from a Windows server and a Linux server. The Windows logs use Event ID 4625 for failed logons, while the Linux logs use 'Failed password'. What must the SIEM do to allow a single correlation rule to detect failed logons from both sources?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.