Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 5Objective 2

Typical Log Sources and Formats SCE Practice Questions (Page 2)

Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 6–10

  1. 6application · medium

    A security analyst is writing a parser for a new log source. The log entries look like this: <134>Mar 1 10:15:30 webserver sshd[1234]: Failed password for root from 192.168.1.10. The analyst needs to extract the timestamp, hostname, process name, and message. Which parsing approach is most appropriate?

    Select an answer first
  2. 7application · easy

    An analyst is reviewing a log entry that contains the following fields: '2025-03-01T12:34:56Z', 'server01', '4625', and 'An account failed to log on'. Which field represents the event ID?

    Select an answer first
  3. 8expert · hard

    A SOC analyst is investigating a possible brute-force attack. The analyst has Syslog logs from a Linux server and Windows Event Logs from a domain controller. The Syslog logs show repeated failed SSH logins, and the Windows logs show repeated failed logon attempts. The analyst needs to determine if the attacks are coming from the same source IP. What is the best way to correlate the logs?

    Select an answer first
  4. 9foundation · easy

    A SOC analyst is reviewing the sources that generate logs in a typical enterprise environment. Which of the following is a common log source that records authentication and access events on a Windows workstation?

    Select an answer first
  5. 10application · medium

    A security analyst is building a centralized log pipeline and needs to ingest logs from a mix of Linux servers, a Cisco ASA firewall, and a custom Java application. The Linux servers and the firewall both support sending logs over UDP port 514, while the Java application writes structured logs to a file. The analyst wants to minimize the number of different ingestion methods and preserve the original log content. Which approach best meets these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.