
NetAppCertified Cyber Resiliency Expert
Domain 5Objective 4
Determine How to Monitor Syslog and Audit Log CERTIFIED-CYBER-RESILIENCY-EXPERT Practice Questions (Page 3)
Part of the Cybersecurity Common Issues domain, which accounts for 18% of the CERTIFIED-CYBER-RESILIENCY-EXPERT exam. NetApp does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–11 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
6concepts
18%of the exam
Questions 11–15
- 11
Which of the following is a standard component of a syslog message?
Select an answer first - 12
A SOC is monitoring syslog messages from a firewall. They notice a sudden increase in 'connection refused' messages from a single internal IP to many external IPs on port 25. What is the most likely interpretation?
Select an answer first - 13
Which monitoring practice is most effective for detecting unauthorized access attempts from syslog and audit logs?
Select an answer first - 14
An analyst is reviewing audit logs and sees a series of events where a user's account is locked out, then unlocked, then locked out again, repeating every few minutes. The user is a high-privilege administrator. What is the most likely explanation?
Select an answer first - 15
A security analyst is reviewing audit logs and notices a series of events where a service account (svc_backup) is enabling and disabling itself repeatedly. Select all the security-relevant conclusions that are appropriate.
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by NetApp. “CERTIFIED-CYBER-RESILIENCY-EXPERT” is a trademark of its owner, used for identification only.