
Certified Information Systems Security Professional
Domain 7Objective 2
7.2 - Conduct Logging and Monitoring Activities CISSP Practice Questions (Page 3)
Part of the Security Operations domain, which accounts for 13% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
12concepts
13%of the exam
Questions 11–15
- 11
A company has deployed a User and Entity Behavior Analytics (UEBA) system to detect insider threats. The UEBA has established a baseline for each user's normal behavior, including login times, data access patterns, and file transfer volumes. Which of the following user activities would the UEBA most likely flag as anomalous?
Select an answer first - 12
Which log analysis technique is used to identify deviations from a known baseline of normal activity?
Select an answer first - 13
Which of the following is a typical use case for a SIEM?
Select an answer first - 14
What is a best practice for tuning a SIEM to reduce false positives?
Select an answer first - 15
Which egress monitoring technique provides information about the volume and flow of network traffic but does not inspect the content of the traffic?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.