
EC-CouncilSOC Essentials
Domain 6Objective 1
SIEM Use Case Development SCE Practice Questions (Page 5)
Part of the Incident Detection and Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
8concepts
Questions 21–25
- 21
A SIEM rule that detects a single user logging into more than five different workstations within an hour is generating false positives because a help desk account legitimately accesses many machines. The help desk account is a shared account used by multiple technicians. What is the best tuning approach?
Select an answer first - 22
A SOC analyst is creating a correlation rule to detect a DDoS attack targeting a public web server. The available data includes NetFlow records, web server access logs, and firewall logs. Which correlation logic is most effective for detecting a volumetric DDoS attack?
Select an answer first - 23
Which action is an example of tuning a SIEM use case?
Select an answer first - 24
A SOC team is building a use case to detect unauthorized use of administrative privileges. They have Active Directory logs, Windows Security logs, and VPN logs. Which data source is most critical for this use case?
Select an answer first - 25
What is the purpose of tuning a SIEM use case?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.