1What is the main purpose of Endpoint Detection and Response (EDR)?
Endpoint Analysis and Threat Hunting: endpoint detection and response
Easy
A.Manage internet subscriptions
B.Create office documents
C.Design computer hardware
D.Monitor and investigate endpoint activity
Correct Answer: Monitor and investigate endpoint activity
Explanation:
EDR tools monitor endpoint activity and help security teams detect, investigate, and respond to threats.
Incorrect! Try again.
2What is malware analysis used to determine?
Endpoint Analysis and Threat Hunting: malware analysis and reverse engineering
Easy
A.The physical size of a server
B.The behavior and purpose of malware
C.The age of a computer monitor
D.The price of a software license
Correct Answer: The behavior and purpose of malware
Explanation:
Malware analysis examines malicious software to understand what it does and how it may affect a system.
Incorrect! Try again.
3What does an asset-focused risk model primarily consider?
Endpoint Analysis and Threat Hunting: data and asset-focused risk models
Easy
A.The value and importance of assets
B.The number of computer keyboards
C.The brand of office furniture
D.The color of network cables
Correct Answer: The value and importance of assets
Explanation:
An asset-focused risk model prioritizes protection based on the value and importance of systems, devices, and data.
Incorrect! Try again.
4Which principle is important for endpoint security?
Endpoint Analysis and Threat Hunting: principles of endpoint security
Easy
A.Allow unknown programs to run
B.Share passwords between users
C.Disable all security monitoring
D.Keep systems updated and protected
Correct Answer: Keep systems updated and protected
Explanation:
Regular updates and security controls help reduce vulnerabilities and protect endpoints from threats.
Incorrect! Try again.
5What is a primary function of a SIEM system?
Security Information and Event Management: fundamentals of SIEM
Easy
A.Increase monitor brightness
B.Replace all network cables
C.Collect and analyze security logs
D.Create graphic design files
Correct Answer: Collect and analyze security logs
Explanation:
A SIEM collects logs from multiple sources and analyzes them to identify possible security events.
Incorrect! Try again.
6What does distributed processing in SIEM generally involve?
Security Information and Event Management: distributed processing
Easy
A.Sharing processing across multiple systems
B.Removing all duplicate user accounts
C.Printing security alerts for manual filing
D.Storing every log on one personal computer
Correct Answer: Sharing processing across multiple systems
Explanation:
Distributed processing divides data collection or analysis among multiple systems to improve scalability and performance.
Incorrect! Try again.
7What is the goal of accelerated threat hunting?
Security Information and Event Management: accelerated threat hunting
Easy
A.Replace backups with temporary files
B.Reduce the number of security analysts
C.Delay investigations until the end of the month
D.Find threats more quickly
Correct Answer: Find threats more quickly
Explanation:
Accelerated threat hunting uses efficient searches, tools, and analytics to identify suspicious activity faster.
Incorrect! Try again.
8How can SIEM support regulatory reporting?
Security Information and Event Management: regulatory reporting with SIEM
Easy
A.By selecting a company's business logo
B.By providing stored security event records
C.By approving employee vacation requests
D.By repairing damaged computer screens
Correct Answer: By providing stored security event records
Explanation:
SIEM records and organizes security events, which can help organizations demonstrate compliance with regulations.
Incorrect! Try again.
9What is infrastructure management in a SIEM environment concerned with?
Security Information and Event Management: infrastructure management
Easy
A.Managing personal social media accounts
B.Ordering food for security staff
C.Choosing colors for presentation slides
D.Maintaining SIEM systems and components
Correct Answer: Maintaining SIEM systems and components
Explanation:
Infrastructure management includes maintaining the servers, data sources, storage, and services that support a SIEM.
Incorrect! Try again.
10What does a SIEM log retention strategy define?
Security Information and Event Management: SIEM log retention strategies
Easy
A.How often monitors should be cleaned
B.How much printer ink should be ordered
C.How many employees may use email
D.How long logs should be kept
Correct Answer: How long logs should be kept
Explanation:
A log retention strategy specifies how long security logs are stored before they are archived or deleted.
Incorrect! Try again.
11What is an example of automated response by a SIEM?
Security Information and Event Management: automated response and remediation
Easy
A.Changing the office lighting schedule
B.Blocking a suspicious network address
C.Writing a report without any event data
D.Replacing a user's keyboard automatically
Correct Answer: Blocking a suspicious network address
Explanation:
Automated response can perform actions such as blocking a suspicious address or disabling a compromised account.
Incorrect! Try again.
12What activity is central to threat hunting with SIEM?
Security Information and Event Management: threat hunting with SIEM
Easy
A.Deleting logs before reviewing them
B.Ignoring unusual login activity
C.Installing unrelated entertainment software
D.Searching logs for suspicious patterns
Correct Answer: Searching logs for suspicious patterns
Explanation:
Threat hunters use SIEM searches and analytics to look for indicators of compromise and unusual behavior.
Incorrect! Try again.
13Which is an operational requirement for an effective SIEM?
Security Information and Event Management: operational requirements
Easy
A.A policy of ignoring low-volume alerts
B.A system that stores events without timestamps
C.A completely disconnected monitoring process
D.Accurate and timely log collection
Correct Answer: Accurate and timely log collection
Explanation:
A SIEM needs accurate, timely, and useful logs to support reliable monitoring and investigation.
Incorrect! Try again.
14What does User and Entity Behavior Analytics (UEBA) examine?
Security Analytics and Machine Learning in SOC: behavioral analytics and UEBA
Easy
A.User and system behavior
B.The physical design of office buildings
C.The speed of document printing
D.The color settings of user interfaces
Correct Answer: User and system behavior
Explanation:
UEBA analyzes the behavior of users and entities, such as devices, to identify unusual or risky activity.
Incorrect! Try again.
15How can machine learning support security analytics?
Security Analytics and Machine Learning in SOC: ML-based security analytics
Easy
A.By eliminating the need for all security policies
B.By replacing every network device with a machine-learning server
C.By identifying patterns in security data
D.By guaranteeing that no future attack can occur
Correct Answer: By identifying patterns in security data
Explanation:
Machine learning can analyze large datasets and identify patterns that may indicate malicious or abnormal activity.
Incorrect! Try again.
16What is the purpose of deploying a predictive security model?
Security Analytics and Machine Learning in SOC: deployment of predictive models
Easy
A.Estimate the likelihood of future threats
B.Prevent analysts from reviewing important security events
C.Guarantee that every alert is correct
D.Remove the need to collect security data
Correct Answer: Estimate the likelihood of future threats
Explanation:
Predictive models use available data to estimate the likelihood of threats or risky events.
Incorrect! Try again.
17What does anomaly detection attempt to identify?
Security Analytics and Machine Learning in SOC: anomaly detection in SOC
Easy
A.Routine events that exactly match established patterns
B.Only events that occur during business hours
C.Activity that differs from normal behavior
D.All activity performed by system administrators
Correct Answer: Activity that differs from normal behavior
Explanation:
Anomaly detection identifies activity that deviates from an established baseline of normal behavior.
Incorrect! Try again.
18Why does a SIEM correlate events from different sources?
Security Information and Event Management: fundamentals of SIEM
Easy
A.To replace authentication with simple usernames
B.To ensure that every alert has the same priority
C.To identify relationships between events
D.To make unrelated events impossible to record
Correct Answer: To identify relationships between events
Explanation:
Correlation connects related events from sources such as servers, firewalls, and endpoints to reveal possible attacks.
Incorrect! Try again.
19What is reverse engineering of malware?
Endpoint Analysis and Threat Hunting: malware analysis and reverse engineering
Easy
A.Transferring malware to production systems for testing
B.Examining how malicious software works
C.Improving the graphics of a security dashboard
D.Deleting every application from an endpoint
Correct Answer: Examining how malicious software works
Explanation:
Reverse engineering examines a program's code or behavior to understand its functions and malicious actions.
Incorrect! Try again.
20What is remediation in incident response?
Security Information and Event Management: automated response and remediation
Easy
A.Collecting unrelated business documents
B.Disabling every security control permanently
C.Increasing the number of unreviewed alerts
D.Fixing or reducing the effects of a threat
Correct Answer: Fixing or reducing the effects of a threat
Explanation:
Remediation removes the threat or reduces its impact, such as by cleaning an infected device or resetting credentials.
Incorrect! Try again.
21An EDR tool detects PowerShell launching from a document reader, followed by credential access and an outbound connection to an unknown domain. What is the most appropriate initial analyst action?
Endpoint Analysis and Threat Hunting: endpoint detection and response
Medium
A.Disable all PowerShell activity across the organization
B.Delete the document reader from the endpoint
C.Close the alert because PowerShell is an approved tool
D.Review the endpoint process tree and related telemetry
Correct Answer: Review the endpoint process tree and related telemetry
Explanation:
The process tree and surrounding telemetry help establish execution sequence, parent-child relationships, persistence, and possible compromise before containment decisions are made.
Incorrect! Try again.
22A suspicious executable shows no network activity during static analysis, but sandbox analysis reveals periodic DNS requests and encrypted outbound traffic. What does this difference most strongly suggest?
Endpoint Analysis and Threat Hunting: malware analysis and reverse engineering
Medium
A.The sample may use runtime behavior or delayed execution
B.The static analysis proves the file is not malicious
C.The file is probably a harmless system utility
D.The sandbox is unable to analyze executable files
Correct Answer: The sample may use runtime behavior or delayed execution
Explanation:
Dynamic analysis can reveal behavior triggered only during execution, such as timers, environment checks, DNS-based command and control, or delayed payload activation.
Incorrect! Try again.
23Two endpoints have the same vulnerability. One stores public marketing files, while the other processes payment information. Which risk-modeling decision is most appropriate?
Endpoint Analysis and Threat Hunting: data and asset-focused risk models
Medium
A.Prioritize the marketing endpoint because it has more files
B.Prioritize the payment endpoint because data impact is higher
C.Assign identical risk because the vulnerability is identical
D.Ignore the vulnerability on both endpoints until exploitation occurs
Correct Answer: Prioritize the payment endpoint because data impact is higher
Explanation:
Asset-focused risk models consider business value, data sensitivity, exposure, and potential impact in addition to technical vulnerability severity.
Incorrect! Try again.
24An organization wants to reduce the impact of compromised user laptops. Which control best applies the principle of least privilege?
Endpoint Analysis and Threat Hunting: principles of endpoint security
Medium
A.Allow unrestricted software installation by users
B.Require users to share one administrator account
C.Provide standard accounts and controlled elevation
D.Give all users local administrator rights
Correct Answer: Provide standard accounts and controlled elevation
Explanation:
Least privilege limits routine accounts to the permissions required for normal work while allowing approved elevation for exceptional administrative tasks.
Incorrect! Try again.
25A SIEM receives authentication, firewall, and endpoint events. Why is normalization important before correlation?
Security Information and Event Management: fundamentals of SIEM
Medium
A.It removes all duplicate events permanently
B.It guarantees that every alert is a confirmed incident
C.It converts different event formats into comparable fields
D.It prevents analysts from viewing raw event data
Correct Answer: It converts different event formats into comparable fields
Explanation:
Normalization maps vendor-specific formats to consistent fields, enabling rules and analytics to compare users, hosts, timestamps, actions, and outcomes across sources.
Incorrect! Try again.
26A global organization sends logs to regional collectors before forwarding selected data to a central SIEM. What is a primary benefit of this design?
Security Information and Event Management: distributed processing
Medium
A.It eliminates the need for time synchronization
B.It reduces latency and distributes ingestion workload
C.It guarantees that no logs will be lost
D.It prevents regional analysts from investigating events
Correct Answer: It reduces latency and distributes ingestion workload
Explanation:
Distributed collectors process data closer to its source, helping manage bandwidth, improve ingestion performance, and reduce delays in geographically dispersed environments.
Incorrect! Try again.
27A threat hunter suspects that a known malicious hash executed during the previous 30 days. Which SIEM capability most directly accelerates the investigation?
Security Information and Event Management: accelerated threat hunting
Medium
A.Reviewing only the latest firewall dashboard
B.Manually opening every endpoint log file
C.Searching indexed endpoint events by file hash
D.Waiting for a new antivirus signature alert
Correct Answer: Searching indexed endpoint events by file hash
Explanation:
Indexed searches allow investigators to query historical telemetry rapidly and identify affected hosts, users, timestamps, and related activity.
Incorrect! Try again.
28An auditor requests evidence of privileged-access reviews for the last quarter. Which SIEM feature best supports this request?
Security Information and Event Management: regulatory reporting with SIEM
Medium
A.A dashboard showing current CPU usage
B.A list of unused software licenses
C.A report based on time-stamped access and review events
D.A monthly count of blocked advertisements
Correct Answer: A report based on time-stamped access and review events
Explanation:
Regulatory reporting requires traceable evidence, including relevant events, timestamps, identities, and review outcomes over the specified period.
Incorrect! Try again.
29A SIEM begins missing events after a new log source is added. Which infrastructure-management check should be performed first?
Security Information and Event Management: infrastructure management
Medium
A.Delete older dashboards from the SIEM
B.Disable time synchronization on all devices
C.Change every detection rule immediately
D.Verify collector capacity and ingestion queues
Correct Answer: Verify collector capacity and ingestion queues
Explanation:
A sudden increase in sources can exceed collector, network, storage, or queue capacity. Checking ingestion health helps identify whether events are being delayed or dropped.
Incorrect! Try again.
30An organization must support investigations for one year but control storage costs. Which retention strategy is most appropriate?
Security Information and Event Management: SIEM log retention strategies
Medium
A.Use tiered storage with searchable recent logs and archived older logs
B.Delete all events after thirty days
C.Keep every event in hot storage for one year
D.Store only alerts and discard supporting events
Correct Answer: Use tiered storage with searchable recent logs and archived older logs
Explanation:
Tiered retention keeps recent data readily searchable while moving older records to lower-cost storage that remains available for investigations and compliance.
Incorrect! Try again.
31A high-confidence alert shows a workstation communicating with a confirmed command-and-control address. Which automated response is most suitable when business disruption must be limited?
Security Information and Event Management: automated response and remediation
Medium
A.Shut down the entire corporate network
B.Isolate the affected workstation from the network
C.Delete all user accounts on the workstation
D.Ignore the alert until a monthly review
Correct Answer: Isolate the affected workstation from the network
Explanation:
Endpoint isolation limits further communication and lateral movement while restricting the impact to the suspected host rather than disrupting the entire organization.
Incorrect! Try again.
32A hunter searches for possible credential theft by examining unusual logins, new service creation, and access to credential stores. Why should these data sources be correlated?
Security Information and Event Management: threat hunting with SIEM
Medium
B.The sources are unrelated but increase dashboard size
C.Correlation removes the need for endpoint investigation
D.Combined evidence can reveal related stages of an attack
Correct Answer: Combined evidence can reveal related stages of an attack
Explanation:
Correlation connects reconnaissance, execution, privilege use, and access activity, producing stronger investigative context than any single event source.
Incorrect! Try again.
33A detection rule compares events from multiple systems but produces incorrect sequences because their clocks differ. Which operational requirement should be addressed?
Security Information and Event Management: operational requirements
Medium
A.Longer usernames for administrators
B.More dashboard color choices
C.Higher screen resolution for analysts
D.Uniform time synchronization across event sources
Correct Answer: Uniform time synchronization across event sources
Explanation:
Accurate and consistent timestamps are essential for event ordering, correlation, incident reconstruction, and reliable detection logic.
Incorrect! Try again.
34A user normally accesses business applications during daytime hours but suddenly downloads a large volume of sensitive files at 2 a.m. UEBA should primarily treat this as:
Security Analytics and Machine Learning in SOC: behavioral analytics and UEBA
Medium
A.A deviation from the user's established behavior
Correct Answer: A deviation from the user's established behavior
Explanation:
UEBA identifies behavior that differs from a learned baseline. The deviation raises risk and requires investigation, but it does not alone prove malicious intent.
Incorrect! Try again.
35A security model detects many true attacks but also generates a large number of false positives. Which evaluation concern is most directly involved?
Security Analytics and Machine Learning in SOC: ML-based security analytics
Medium
A.The age of the operating system license
B.The number of dashboard widgets
C.The physical size of the training servers
D.The balance between precision and recall
Correct Answer: The balance between precision and recall
Explanation:
Recall measures how many relevant attacks are detected, while precision measures how many alerts are actually relevant. Improving one can affect the other.
Incorrect! Try again.
36Before deploying a predictive security model into production, which step best reduces operational risk?
Security Analytics and Machine Learning in SOC: deployment of predictive models
Medium
A.Disable logging so model decisions remain private
B.Test it on representative data and monitor performance
C.Deploy it directly with automatic account disabling
D.Train it only on one analyst's favorite incidents
Correct Answer: Test it on representative data and monitor performance
Explanation:
Validation with representative data helps identify accuracy, drift, bias, and false-positive issues before the model can trigger disruptive production actions.
Incorrect! Try again.
37A network anomaly detector flags a server because outbound traffic is five times its normal baseline during a scheduled backup. What should the analyst do first?
Security Analytics and Machine Learning in SOC: anomaly detection in SOC
Medium
A.Remove the server from anomaly monitoring
B.Confirm the activity against the backup schedule
C.Classify the event as an attack without review
D.Block all traffic from the server permanently
Correct Answer: Confirm the activity against the backup schedule
Explanation:
Anomalies indicate deviations from expected behavior, not confirmed attacks. Checking known operational context helps distinguish legitimate activity from suspicious behavior.
Incorrect! Try again.
38A correlation rule detects five failed logins followed by a successful login from a new country and an administrative action. Which additional field is most useful for reducing ambiguity?
Security Information and Event Management: fundamentals of SIEM
Medium
A.The authenticated user's identity and source device
B.The analyst's preferred report format
C.The SIEM dashboard's background color
D.The total number of installed printers
Correct Answer: The authenticated user's identity and source device
Explanation:
Identity and source-device context help determine whether the sequence belongs to a legitimate user, a compromised account, or an unusual access path.
Incorrect! Try again.
39Why should an automated SIEM playbook require approval before disabling a high-value service account when alert confidence is moderate?
Security Information and Event Management: automated response and remediation
Medium
A.Approval helps limit business impact from false positives
B.Approval makes event timestamps unnecessary
C.Approval prevents analysts from reviewing evidence
D.Approval guarantees that the alert is malicious
Correct Answer: Approval helps limit business impact from false positives
Explanation:
Human approval adds a control point for actions that could interrupt critical operations, especially when detection confidence is not sufficiently high.
Incorrect! Try again.
40A regional SIEM collector continues receiving logs during a temporary loss of connectivity to the central platform. Which design feature provides this resilience?
Security Information and Event Management: distributed processing
Medium
A.Disabling collection during connectivity failures
B.Local buffering and store-and-forward processing
C.Dependence on a single central network path
D.Immediate deletion of unsent events
Correct Answer: Local buffering and store-and-forward processing
Explanation:
Local buffering preserves events during outages and forwards them when connectivity returns, reducing data loss and maintaining investigative continuity.
Incorrect! Try again.
41An EDR platform observes a signed office application spawning PowerShell, which launches an encoded command and accesses a credential database. The process is later deleted. Which detection approach is most resilient to the deletion of the executable?
Endpoint Analysis and Threat Hunting: endpoint detection and response
Hard
A.Alert only when the deleted file is recovered
B.Block every signed office application
C.Match the executable's SHA-256 hash
D.Correlate process ancestry, command-line behavior, and access patterns
Correct Answer: Correlate process ancestry, command-line behavior, and access patterns
Explanation:
Behavioral and lineage-based telemetry remains useful after a file is deleted or modified, whereas hash-based detection depends on the artifact remaining available.
Incorrect! Try again.
42A sample performs no suspicious activity in an automated sandbox but is malicious in a victim environment. Which analysis strategy best tests for environment-aware evasion?
Endpoint Analysis and Threat Hunting: malware analysis and reverse engineering
Hard
A.Increase the sandbox's disk capacity
B.Execute it repeatedly with the same sandbox profile
C.Vary timing, user activity, system artifacts, and network responses
D.Compare only the sample's static import table
Correct Answer: Vary timing, user activity, system artifacts, and network responses
Explanation:
Malware may detect virtualization, missing user activity, unrealistic timing, or absent network infrastructure. Varying those conditions exposes environment-sensitive behavior.
Incorrect! Try again.
43An organization must prioritize remediation among four assets. Asset A has high exploitability but contains public data; Asset B has moderate exploitability and stores regulated customer records; Asset C has low exploitability and supports a critical production process; Asset D has high exploitability but is isolated and disposable. Which modeling principle should dominate prioritization?
Endpoint Analysis and Threat Hunting: data and asset-focused risk models
Hard
A.Rank assets by purchase price and replacement cost
B.Rank assets by expected business impact and exposure
C.Rank assets by the number of installed applications
D.Rank assets only by vulnerability severity
Correct Answer: Rank assets by expected business impact and exposure
Explanation:
Risk models should combine threat likelihood, exposure, asset criticality, and data sensitivity. Vulnerability severity alone does not represent organizational loss.
Incorrect! Try again.
44A workstation requires local administrator privileges for a legacy application, and application replacement is not immediately possible. Which compensating control most directly limits the resulting endpoint risk?
Endpoint Analysis and Threat Hunting: principles of endpoint security
Hard
A.Allow elevation only for the approved application and task
B.Permit unrestricted outbound network access
C.Share one administrator account across support staff
D.Disable endpoint logging to reduce performance overhead
Correct Answer: Allow elevation only for the approved application and task
Explanation:
Just-in-time or application-specific elevation limits the scope and duration of privileged access while preserving required functionality.
Incorrect! Try again.
45A SIEM receives authentication events from systems using different time zones and inconsistent event schemas. Which capability is most important before reliable cross-source correlation?
Security Information and Event Management: fundamentals of SIEM
Hard
A.Dashboard customization
B.Longer alert descriptions
C.Event normalization and time synchronization
D.Higher storage compression
Correct Answer: Event normalization and time synchronization
Explanation:
Correlation depends on comparable fields and accurate event order. Normalization and synchronized timestamps prevent false relationships and missed attack sequences.
Incorrect! Try again.
46A distributed SIEM uses regional collectors that continue receiving logs during a temporary loss of connectivity to the central analytics cluster. Which design property best prevents data loss and preserves later correlation?
Security Information and Event Management: distributed processing
Hard
A.Local buffering with durable queues and ordered replay
B.Compression followed by sampling of high-volume events
C.Stateless forwarding with immediate deletion
D.Independent regional dashboards without central indexing
Correct Answer: Local buffering with durable queues and ordered replay
Explanation:
Durable local queues absorb outages and allow events to be replayed in order, preserving evidence for central processing once connectivity returns.
Incorrect! Try again.
47A hunter suspects that an attacker used a rare parent-child process relationship across thousands of endpoints. Which SIEM feature most directly accelerates investigation?
Security Information and Event Management: accelerated threat hunting
Hard
A.Manual export of every endpoint event
B.A dashboard showing only aggregate event counts
C.Precomputed behavioral indexes and pivotable entity relationships
D.Full-text search over unindexed raw logs
Correct Answer: Precomputed behavioral indexes and pivotable entity relationships
Explanation:
Indexes and entity relationships reduce search time and let analysts pivot from a process to a host, user, hash, or related activity quickly.
Incorrect! Try again.
48A compliance report must demonstrate that privileged access reviews occurred monthly and that the underlying records were not altered. Which SIEM implementation best supports this requirement?
Security Information and Event Management: regulatory reporting with SIEM
Hard
A.Use immutable evidence storage with time-stamped audit trails
B.Store only monthly review totals
C.Retain alerts without their source authentication records
D.Allow administrators to edit events after ingestion
Correct Answer: Use immutable evidence storage with time-stamped audit trails
Explanation:
Regulatory evidence requires traceability and integrity. Immutable records, timestamps, and access logs support both review verification and tamper detection.
Incorrect! Try again.
49A SIEM's ingestion rate is stable, but query latency increases sharply whenever a new log source is onboarded. Which infrastructure investigation is most appropriate first?
Security Information and Event Management: infrastructure management
Hard
A.Measure ingestion, parsing, indexing, storage, and query resource contention
B.Increase alert severity thresholds
C.Replace all source systems with identical hardware
The bottleneck may occur at any processing stage. Component-level telemetry identifies whether onboarding is exhausting CPU, memory, I/O, indexing, or query capacity.
Incorrect! Try again.
50An organization needs rapid investigation for 30 days, searchable compliance evidence for one year, and low-cost preservation for seven years. Which retention architecture best fits these requirements?
Security Information and Event Management: SIEM log retention strategies
Hard
A.Keep every event in hot storage for seven years
B.Retain only normalized fields and discard source records
C.Delete raw events after alerts are generated
D.Use tiered retention with hot, warm, and immutable archival storage
Correct Answer: Use tiered retention with hot, warm, and immutable archival storage
Explanation:
Tiering aligns storage cost and query performance with access requirements while preserving long-term evidence and original records.
Incorrect! Try again.
51A SIEM detects a possible account takeover, but the account belongs to an emergency-response engineer. Which automation design best balances containment and operational risk?
Security Information and Event Management: automated response and remediation
Hard
A.Require risk-based approval or step-up verification before disruptive action
B.Automatically delete the account's recent authentication history
C.Ignore all alerts involving emergency-response accounts
D.Disable the account immediately for every matching alert
Correct Answer: Require risk-based approval or step-up verification before disruptive action
Explanation:
High-impact accounts need safeguards against false positives. Risk-based confirmation can contain credible threats without unnecessarily interrupting critical operations.
Incorrect! Try again.
52A hunter finds a suspicious domain in DNS logs but cannot determine whether the activity was malicious. Which next pivot provides the strongest contextual enrichment?
Security Information and Event Management: threat hunting with SIEM
Hard
A.Count how many times the domain appears in the dashboard
B.Block the domain before collecting additional evidence
C.Search for the domain only in firewall deny logs
D.Correlate DNS requests with endpoint processes, users, and subsequent connections
Correct Answer: Correlate DNS requests with endpoint processes, users, and subsequent connections
Explanation:
Process, identity, and follow-on network context can distinguish browser noise from malware-driven command-and-control activity.
Incorrect! Try again.
53A SOC has frequent alert backlogs because rules generate duplicate alerts for the same incident across multiple sources. Which operational improvement most directly addresses the problem?
Security Information and Event Management: operational requirements
Hard
A.Reduce the retention period for all security logs
B.Increase the number of unreviewed detection rules
C.Define deduplication, ownership, severity, escalation, and service-level procedures
D.Send every alert to all analysts simultaneously
Correct Answer: Define deduplication, ownership, severity, escalation, and service-level procedures
Explanation:
Operational requirements determine how alerts are grouped, assigned, prioritized, and handled. These controls reduce duplicate work and clarify response accountability.
Incorrect! Try again.
54A user normally accesses systems from one country during business hours but suddenly authenticates from another country using a new device and downloads an unusual volume of sensitive data. Why is UEBA more useful than a static allowlist in this case?
Security Analytics and Machine Learning in SOC: behavioral analytics and UEBA
Hard
A.UEBA replaces the need for authentication controls
B.UEBA evaluates deviations across identity, device, time, location, and activity
C.UEBA detects only known malicious file hashes
D.UEBA approves every login from a previously observed country
Correct Answer: UEBA evaluates deviations across identity, device, time, location, and activity
Explanation:
UEBA builds behavioral baselines and combines multiple contextual deviations, allowing it to identify suspicious activity that does not match a fixed signature.
Incorrect! Try again.
55A classifier achieves 99.5% accuracy on a test set where only 0.1% of events are malicious. Which conclusion is most defensible?
Security Analytics and Machine Learning in SOC: ML-based security analytics
Hard
A.The model is operationally excellent
B.The model has detected nearly all attacks
C.Accuracy alone is insufficient; precision, recall, and class imbalance must be examined
D.The test set proves the model has no false positives
Correct Answer: Accuracy alone is insufficient; precision, recall, and class imbalance must be examined
Explanation:
With extreme class imbalance, a model can achieve high accuracy by predicting the majority class. Precision, recall, and related metrics better characterize detection utility.
Incorrect! Try again.
56A predictive model was trained on historical data collected before a major cloud migration. After deployment, feature distributions shift substantially. What is the primary risk?
Security Analytics and Machine Learning in SOC: deployment of predictive models
Hard
A.The model becomes deterministic and therefore more accurate
B.Encryption automatically corrects the predictions
C.Concept or data drift can reduce model validity
D.More storage guarantees higher recall
Correct Answer: Concept or data drift can reduce model validity
Explanation:
Changes in telemetry, user behavior, infrastructure, or attacker behavior can make training patterns unrepresentative, requiring monitoring and possible retraining.
Incorrect! Try again.
57An unsupervised detector flags a large number of anomalies immediately after a company-wide shift to remote work. What is the best first response?
Security Analytics and Machine Learning in SOC: anomaly detection in SOC
Hard
A.Raise the threshold until no anomalies remain
B.Validate the baseline against the operational change and retrain or segment it
C.Disable all anomaly detection permanently
D.Treat every anomaly as a confirmed incident
Correct Answer: Validate the baseline against the operational change and retrain or segment it
Explanation:
Anomaly detectors interpret major legitimate changes as deviations. The baseline should incorporate the new behavior or use separate context-aware populations.
Incorrect! Try again.
58A privileged service account performs thousands of successful logins daily, making volume-based UEBA alerts noisy. Which refinement is most appropriate?
Security Analytics and Machine Learning in SOC: behavioral analytics and UEBA
Hard
A.Apply the same baseline used for human employees
B.Model its expected peers, destinations, schedules, and authentication methods
C.Alert only when the account fails one password attempt
D.Exclude the service account from all monitoring
Correct Answer: Model its expected peers, destinations, schedules, and authentication methods
Explanation:
Service accounts have different behavior from human users. A role-specific baseline reduces false positives while preserving detection of unusual destinations, timing, or methods.
Incorrect! Try again.
59A SIEM distributes events by source region, but an attacker's activity spans two regions and the correlation rule runs independently in each partition. What architectural issue does this reveal?
Security Information and Event Management: distributed processing
Hard
A.The event fields are necessarily over-normalized
B.The collectors are using too much compression
C.The system lacks cross-partition state or global correlation
D.The archive tier is too inexpensive
Correct Answer: The system lacks cross-partition state or global correlation
Explanation:
Partition-local processing can miss multi-region attack chains. Global correlation, replicated state, or an appropriate repartitioning strategy is required.
Incorrect! Try again.
60An automated playbook isolates an endpoint after detecting ransomware-like behavior. The endpoint may contain volatile evidence needed for investigation. Which playbook change is most appropriate?
Security Information and Event Management: automated response and remediation
Hard
A.Delete suspicious files before collecting metadata
B.Perform evidence-preserving collection before or during isolation
C.Power off every endpoint in the same network segment
D.Suppress the event to avoid disrupting the user
Correct Answer: Perform evidence-preserving collection before or during isolation
Explanation:
Response should contain the threat while preserving volatile memory, process, network, and file metadata needed for scoping and forensic analysis.
Incorrect! Try again.
Did this save you a night before the exam?
LPU Notes is free, and it stays free. Ads cover part of the server bill.
The rest comes out of a student's own pocket: the domain, the storage,
and keeping the site up through the weeks everyone needs it at once.
The payment button didn't load. An ad blocker or a filtered network is the usual reason.
to try again.
Nothing here is ever locked, and nothing unlocks. Chip in only if it was worth it.
What it pays for →