
EC-CouncilSOC Essentials
Domain 5Objective 2
Typical Log Sources and Formats SCE Practice Questions (Page 5)
Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 21–25
- 21
A log entry contains the following fields: "2025-03-01 14:22:10", "server01", "4625", and "The user failed to log on." Which field represents the message component of the log entry?
Select an answer first - 22
A company is integrating a new cloud-based identity provider (IdP) that logs authentication events in JSON format. The existing SIEM ingests Syslog and Windows Event Log natively, but does not have a JSON connector. The team has a small budget and needs to start collecting these logs quickly. Which approach is most efficient?
Select an answer first - 23
An analyst is reviewing logs from a web application firewall (WAF) and a database server. The WAF logs are in JSON format, while the database logs are in plain text with a custom delimiter. The analyst needs to search for SQL injection attempts across both sources. What is the most efficient approach?
Select an answer first - 24
Which of the following is a typical log source that would provide information about attempted connections blocked by a security tool?
Select an answer first - 25
In a log entry, which field is used to identify the specific type of event that occurred, such as a login failure or a process termination?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.