
EC-CouncilSOC Essentials
Domain 5Objective 2
Typical Log Sources and Formats SCE Practice Questions (Page 7)
Part of the Log Management domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 1–2 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 31–35
- 31
Which log format is commonly associated with network devices and Linux systems, and typically includes a timestamp, hostname, and a plain-text message?
Select an answer first - 32
A SOC analyst is reviewing logs from multiple sources in a SIEM. One log entry appears as: {"timestamp":"2025-03-01T10:15:30Z","source_ip":"192.168.1.10","event_id":4625,"message":"An account failed to log on"}. Another entry appears as: <134>Mar 1 10:15:30 webserver sshd[1234]: Failed password for root from 192.168.1.10. The analyst needs to correlate these two entries to identify a brute-force attack. Which statement accurately describes the two formats?
Select an answer first - 33
A Windows administrator needs to forward security-related events from domain controllers to a SIEM. The SIEM requires a structured format that preserves event IDs and message details. Which log source and format should the administrator use?
Select an answer first - 34
A SOC analyst is creating a dashboard to monitor the health of the IT environment. The dashboard should show: (1) failed login attempts, (2) CPU usage on servers, (3) firewall denies, and (4) application errors. Which log categories should the analyst include?
Select an answer first - 35
A SOC analyst is investigating a possible brute-force attack. They have logs from a firewall, a web server, and a domain controller. The firewall logs show repeated connection attempts from a single IP, the web server logs show HTTP 401 responses, and the domain controller logs show many failed logon events. The analyst needs to prove that the same IP is responsible for all three. Which field is most critical for correlation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.