Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 4Objective 4

SIEM Deployment Models and Data Sources SCE Practice Questions (Page 7)

Part of the SOC Components and Architecture domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
4concepts

Questions 31–35

  1. 31expert · hard

    A SIEM is receiving logs from multiple sources, but the field names for IP addresses differ (e.g., src_ip, source_address, SRC). An analyst writes a correlation rule that only uses 'src_ip'. What is the likely result?

    Select an answer first
  2. 32expert · hard

    A company with a mature on-premises SIEM wants to add cloud-based threat intelligence feeds and automated response capabilities without moving its existing log storage. Which deployment model would allow this while preserving the existing SIEM investment?

    Select an answer first
  3. 33application · medium

    A SIEM is configured to collect logs from a network device that only supports syslog. What is the most common method for the SIEM to receive these logs?

    Select an answer first
  4. 34application · hard

    A multinational company operates data centers in the EU and the US. They must keep EU customer data within the EU for compliance. They want a single SIEM view for their global SOC. Which deployment model best meets these requirements?

    Select an answer first
  5. 35expert · hard

    A company is deploying a SIEM and has a limited budget. They have two data sources: a legacy mainframe that only supports syslog over UDP and a modern cloud application that sends JSON logs via HTTPS. The SIEM vendor charges per GB ingested. The mainframe generates 500 GB/day of verbose syslog, while the cloud app generates 10 GB/day of high-value security logs. The SOC wants to maximize detection value within budget. What should they do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.