Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 5Objective 2

Typical Log Sources and Formats SCE Practice Questions (Page 6)

Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 26–30

  1. 26application · medium

    A network administrator is troubleshooting a connectivity issue and needs to determine whether the problem is on the local network or the internet. Which log source would provide the most relevant information?

    Select an answer first
  2. 27application · medium

    A security analyst is investigating a malware infection on a Windows workstation. The analyst finds a Windows Event Log entry with Event ID 4688 (process creation) that includes the command line of the executed process. The analyst needs to determine if the process was launched with administrative privileges. Which field in the event log entry would provide this information?

    Select an answer first
  3. 28application · medium

    An organization is deploying a new SIEM and needs to ingest logs from a variety of sources. The sources include: a Linux web server, a Windows domain controller, a Cisco switch, and an AWS CloudTrail. The SIEM supports Syslog, Windows Event Log, and JSON via API. Which combination of ingestion methods should the analyst use?

    Select an answer first
  4. 29expert · hard · select all that apply

    A SOC team is reviewing their log sources to ensure they can detect a wide range of attacks. They want to include logs that cover network, system, application, and security categories. Which two log sources should they add to achieve this coverage? Select all that apply.

    Select an answer first
  5. 30expert · hard

    A security analyst is reviewing a log entry from a database server that shows: 2025-03-01 10:15:30, user=app_user, action=SELECT, table=customers, rows=1000. The analyst is investigating a potential data breach. Which field is most critical for determining the scope of the breach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.