Unit 3: Endpoint, SIEM, and Security Analytics - Practice Quiz

INT244 — Securing Computing Systems 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What is the main purpose of Endpoint Detection and Response (EDR)?

Endpoint Analysis and Threat Hunting: endpoint detection and response Easy
A. Manage internet subscriptions
B. Create office documents
C. Design computer hardware
D. Monitor and investigate endpoint activity

2 What is malware analysis used to determine?

Endpoint Analysis and Threat Hunting: malware analysis and reverse engineering Easy
A. The physical size of a server
B. The behavior and purpose of malware
C. The age of a computer monitor
D. The price of a software license

3 What does an asset-focused risk model primarily consider?

Endpoint Analysis and Threat Hunting: data and asset-focused risk models Easy
A. The value and importance of assets
B. The number of computer keyboards
C. The brand of office furniture
D. The color of network cables

4 Which principle is important for endpoint security?

Endpoint Analysis and Threat Hunting: principles of endpoint security Easy
A. Allow unknown programs to run
B. Share passwords between users
C. Disable all security monitoring
D. Keep systems updated and protected

5 What is a primary function of a SIEM system?

Security Information and Event Management: fundamentals of SIEM Easy
A. Increase monitor brightness
B. Replace all network cables
C. Collect and analyze security logs
D. Create graphic design files

6 What does distributed processing in SIEM generally involve?

Security Information and Event Management: distributed processing Easy
A. Sharing processing across multiple systems
B. Removing all duplicate user accounts
C. Printing security alerts for manual filing
D. Storing every log on one personal computer

7 What is the goal of accelerated threat hunting?

Security Information and Event Management: accelerated threat hunting Easy
A. Replace backups with temporary files
B. Reduce the number of security analysts
C. Delay investigations until the end of the month
D. Find threats more quickly

8 How can SIEM support regulatory reporting?

Security Information and Event Management: regulatory reporting with SIEM Easy
A. By selecting a company's business logo
B. By providing stored security event records
C. By approving employee vacation requests
D. By repairing damaged computer screens

9 What is infrastructure management in a SIEM environment concerned with?

Security Information and Event Management: infrastructure management Easy
A. Managing personal social media accounts
B. Ordering food for security staff
C. Choosing colors for presentation slides
D. Maintaining SIEM systems and components

10 What does a SIEM log retention strategy define?

Security Information and Event Management: SIEM log retention strategies Easy
A. How often monitors should be cleaned
B. How much printer ink should be ordered
C. How many employees may use email
D. How long logs should be kept

11 What is an example of automated response by a SIEM?

Security Information and Event Management: automated response and remediation Easy
A. Changing the office lighting schedule
B. Blocking a suspicious network address
C. Writing a report without any event data
D. Replacing a user's keyboard automatically

12 What activity is central to threat hunting with SIEM?

Security Information and Event Management: threat hunting with SIEM Easy
A. Deleting logs before reviewing them
B. Ignoring unusual login activity
C. Installing unrelated entertainment software
D. Searching logs for suspicious patterns

13 Which is an operational requirement for an effective SIEM?

Security Information and Event Management: operational requirements Easy
A. A policy of ignoring low-volume alerts
B. A system that stores events without timestamps
C. A completely disconnected monitoring process
D. Accurate and timely log collection

14 What does User and Entity Behavior Analytics (UEBA) examine?

Security Analytics and Machine Learning in SOC: behavioral analytics and UEBA Easy
A. User and system behavior
B. The physical design of office buildings
C. The speed of document printing
D. The color settings of user interfaces

15 How can machine learning support security analytics?

Security Analytics and Machine Learning in SOC: ML-based security analytics Easy
A. By eliminating the need for all security policies
B. By replacing every network device with a machine-learning server
C. By identifying patterns in security data
D. By guaranteeing that no future attack can occur

16 What is the purpose of deploying a predictive security model?

Security Analytics and Machine Learning in SOC: deployment of predictive models Easy
A. Estimate the likelihood of future threats
B. Prevent analysts from reviewing important security events
C. Guarantee that every alert is correct
D. Remove the need to collect security data

17 What does anomaly detection attempt to identify?

Security Analytics and Machine Learning in SOC: anomaly detection in SOC Easy
A. Routine events that exactly match established patterns
B. Only events that occur during business hours
C. Activity that differs from normal behavior
D. All activity performed by system administrators

18 Why does a SIEM correlate events from different sources?

Security Information and Event Management: fundamentals of SIEM Easy
A. To replace authentication with simple usernames
B. To ensure that every alert has the same priority
C. To identify relationships between events
D. To make unrelated events impossible to record

19 What is reverse engineering of malware?

Endpoint Analysis and Threat Hunting: malware analysis and reverse engineering Easy
A. Transferring malware to production systems for testing
B. Examining how malicious software works
C. Improving the graphics of a security dashboard
D. Deleting every application from an endpoint

20 What is remediation in incident response?

Security Information and Event Management: automated response and remediation Easy
A. Collecting unrelated business documents
B. Disabling every security control permanently
C. Increasing the number of unreviewed alerts
D. Fixing or reducing the effects of a threat

21 An EDR tool detects PowerShell launching from a document reader, followed by credential access and an outbound connection to an unknown domain. What is the most appropriate initial analyst action?

Endpoint Analysis and Threat Hunting: endpoint detection and response Medium
A. Disable all PowerShell activity across the organization
B. Delete the document reader from the endpoint
C. Close the alert because PowerShell is an approved tool
D. Review the endpoint process tree and related telemetry

22 A suspicious executable shows no network activity during static analysis, but sandbox analysis reveals periodic DNS requests and encrypted outbound traffic. What does this difference most strongly suggest?

Endpoint Analysis and Threat Hunting: malware analysis and reverse engineering Medium
A. The sample may use runtime behavior or delayed execution
B. The static analysis proves the file is not malicious
C. The file is probably a harmless system utility
D. The sandbox is unable to analyze executable files

23 Two endpoints have the same vulnerability. One stores public marketing files, while the other processes payment information. Which risk-modeling decision is most appropriate?

Endpoint Analysis and Threat Hunting: data and asset-focused risk models Medium
A. Prioritize the marketing endpoint because it has more files
B. Prioritize the payment endpoint because data impact is higher
C. Assign identical risk because the vulnerability is identical
D. Ignore the vulnerability on both endpoints until exploitation occurs

24 An organization wants to reduce the impact of compromised user laptops. Which control best applies the principle of least privilege?

Endpoint Analysis and Threat Hunting: principles of endpoint security Medium
A. Allow unrestricted software installation by users
B. Require users to share one administrator account
C. Provide standard accounts and controlled elevation
D. Give all users local administrator rights

25 A SIEM receives authentication, firewall, and endpoint events. Why is normalization important before correlation?

Security Information and Event Management: fundamentals of SIEM Medium
A. It removes all duplicate events permanently
B. It guarantees that every alert is a confirmed incident
C. It converts different event formats into comparable fields
D. It prevents analysts from viewing raw event data

26 A global organization sends logs to regional collectors before forwarding selected data to a central SIEM. What is a primary benefit of this design?

Security Information and Event Management: distributed processing Medium
A. It eliminates the need for time synchronization
B. It reduces latency and distributes ingestion workload
C. It guarantees that no logs will be lost
D. It prevents regional analysts from investigating events

27 A threat hunter suspects that a known malicious hash executed during the previous 30 days. Which SIEM capability most directly accelerates the investigation?

Security Information and Event Management: accelerated threat hunting Medium
A. Reviewing only the latest firewall dashboard
B. Manually opening every endpoint log file
C. Searching indexed endpoint events by file hash
D. Waiting for a new antivirus signature alert

28 An auditor requests evidence of privileged-access reviews for the last quarter. Which SIEM feature best supports this request?

Security Information and Event Management: regulatory reporting with SIEM Medium
A. A dashboard showing current CPU usage
B. A list of unused software licenses
C. A report based on time-stamped access and review events
D. A monthly count of blocked advertisements

29 A SIEM begins missing events after a new log source is added. Which infrastructure-management check should be performed first?

Security Information and Event Management: infrastructure management Medium
A. Delete older dashboards from the SIEM
B. Disable time synchronization on all devices
C. Change every detection rule immediately
D. Verify collector capacity and ingestion queues

30 An organization must support investigations for one year but control storage costs. Which retention strategy is most appropriate?

Security Information and Event Management: SIEM log retention strategies Medium
A. Use tiered storage with searchable recent logs and archived older logs
B. Delete all events after thirty days
C. Keep every event in hot storage for one year
D. Store only alerts and discard supporting events

31 A high-confidence alert shows a workstation communicating with a confirmed command-and-control address. Which automated response is most suitable when business disruption must be limited?

Security Information and Event Management: automated response and remediation Medium
A. Shut down the entire corporate network
B. Isolate the affected workstation from the network
C. Delete all user accounts on the workstation
D. Ignore the alert until a monthly review

32 A hunter searches for possible credential theft by examining unusual logins, new service creation, and access to credential stores. Why should these data sources be correlated?

Security Information and Event Management: threat hunting with SIEM Medium
A. Each source independently proves credential theft
B. The sources are unrelated but increase dashboard size
C. Correlation removes the need for endpoint investigation
D. Combined evidence can reveal related stages of an attack

33 A detection rule compares events from multiple systems but produces incorrect sequences because their clocks differ. Which operational requirement should be addressed?

Security Information and Event Management: operational requirements Medium
A. Longer usernames for administrators
B. More dashboard color choices
C. Higher screen resolution for analysts
D. Uniform time synchronization across event sources

34 A user normally accesses business applications during daytime hours but suddenly downloads a large volume of sensitive files at 2 a.m. UEBA should primarily treat this as:

Security Analytics and Machine Learning in SOC: behavioral analytics and UEBA Medium
A. A deviation from the user's established behavior
B. A normal event because the account is valid
C. A failed authentication requiring password reset
D. A guaranteed malicious action

35 A security model detects many true attacks but also generates a large number of false positives. Which evaluation concern is most directly involved?

Security Analytics and Machine Learning in SOC: ML-based security analytics Medium
A. The age of the operating system license
B. The number of dashboard widgets
C. The physical size of the training servers
D. The balance between precision and recall

36 Before deploying a predictive security model into production, which step best reduces operational risk?

Security Analytics and Machine Learning in SOC: deployment of predictive models Medium
A. Disable logging so model decisions remain private
B. Test it on representative data and monitor performance
C. Deploy it directly with automatic account disabling
D. Train it only on one analyst's favorite incidents

37 A network anomaly detector flags a server because outbound traffic is five times its normal baseline during a scheduled backup. What should the analyst do first?

Security Analytics and Machine Learning in SOC: anomaly detection in SOC Medium
A. Remove the server from anomaly monitoring
B. Confirm the activity against the backup schedule
C. Classify the event as an attack without review
D. Block all traffic from the server permanently

38 A correlation rule detects five failed logins followed by a successful login from a new country and an administrative action. Which additional field is most useful for reducing ambiguity?

Security Information and Event Management: fundamentals of SIEM Medium
A. The authenticated user's identity and source device
B. The analyst's preferred report format
C. The SIEM dashboard's background color
D. The total number of installed printers

39 Why should an automated SIEM playbook require approval before disabling a high-value service account when alert confidence is moderate?

Security Information and Event Management: automated response and remediation Medium
A. Approval helps limit business impact from false positives
B. Approval makes event timestamps unnecessary
C. Approval prevents analysts from reviewing evidence
D. Approval guarantees that the alert is malicious

40 A regional SIEM collector continues receiving logs during a temporary loss of connectivity to the central platform. Which design feature provides this resilience?

Security Information and Event Management: distributed processing Medium
A. Disabling collection during connectivity failures
B. Local buffering and store-and-forward processing
C. Dependence on a single central network path
D. Immediate deletion of unsent events

41 An EDR platform observes a signed office application spawning PowerShell, which launches an encoded command and accesses a credential database. The process is later deleted. Which detection approach is most resilient to the deletion of the executable?

Endpoint Analysis and Threat Hunting: endpoint detection and response Hard
A. Alert only when the deleted file is recovered
B. Block every signed office application
C. Match the executable's SHA-256 hash
D. Correlate process ancestry, command-line behavior, and access patterns

42 A sample performs no suspicious activity in an automated sandbox but is malicious in a victim environment. Which analysis strategy best tests for environment-aware evasion?

Endpoint Analysis and Threat Hunting: malware analysis and reverse engineering Hard
A. Increase the sandbox's disk capacity
B. Execute it repeatedly with the same sandbox profile
C. Vary timing, user activity, system artifacts, and network responses
D. Compare only the sample's static import table

43 An organization must prioritize remediation among four assets. Asset A has high exploitability but contains public data; Asset B has moderate exploitability and stores regulated customer records; Asset C has low exploitability and supports a critical production process; Asset D has high exploitability but is isolated and disposable. Which modeling principle should dominate prioritization?

Endpoint Analysis and Threat Hunting: data and asset-focused risk models Hard
A. Rank assets by purchase price and replacement cost
B. Rank assets by expected business impact and exposure
C. Rank assets by the number of installed applications
D. Rank assets only by vulnerability severity

44 A workstation requires local administrator privileges for a legacy application, and application replacement is not immediately possible. Which compensating control most directly limits the resulting endpoint risk?

Endpoint Analysis and Threat Hunting: principles of endpoint security Hard
A. Allow elevation only for the approved application and task
B. Permit unrestricted outbound network access
C. Share one administrator account across support staff
D. Disable endpoint logging to reduce performance overhead

45 A SIEM receives authentication events from systems using different time zones and inconsistent event schemas. Which capability is most important before reliable cross-source correlation?

Security Information and Event Management: fundamentals of SIEM Hard
A. Dashboard customization
B. Longer alert descriptions
C. Event normalization and time synchronization
D. Higher storage compression

46 A distributed SIEM uses regional collectors that continue receiving logs during a temporary loss of connectivity to the central analytics cluster. Which design property best prevents data loss and preserves later correlation?

Security Information and Event Management: distributed processing Hard
A. Local buffering with durable queues and ordered replay
B. Compression followed by sampling of high-volume events
C. Stateless forwarding with immediate deletion
D. Independent regional dashboards without central indexing

47 A hunter suspects that an attacker used a rare parent-child process relationship across thousands of endpoints. Which SIEM feature most directly accelerates investigation?

Security Information and Event Management: accelerated threat hunting Hard
A. Manual export of every endpoint event
B. A dashboard showing only aggregate event counts
C. Precomputed behavioral indexes and pivotable entity relationships
D. Full-text search over unindexed raw logs

48 A compliance report must demonstrate that privileged access reviews occurred monthly and that the underlying records were not altered. Which SIEM implementation best supports this requirement?

Security Information and Event Management: regulatory reporting with SIEM Hard
A. Use immutable evidence storage with time-stamped audit trails
B. Store only monthly review totals
C. Retain alerts without their source authentication records
D. Allow administrators to edit events after ingestion

49 A SIEM's ingestion rate is stable, but query latency increases sharply whenever a new log source is onboarded. Which infrastructure investigation is most appropriate first?

Security Information and Event Management: infrastructure management Hard
A. Measure ingestion, parsing, indexing, storage, and query resource contention
B. Increase alert severity thresholds
C. Replace all source systems with identical hardware
D. Disable correlation rules permanently

50 An organization needs rapid investigation for 30 days, searchable compliance evidence for one year, and low-cost preservation for seven years. Which retention architecture best fits these requirements?

Security Information and Event Management: SIEM log retention strategies Hard
A. Keep every event in hot storage for seven years
B. Retain only normalized fields and discard source records
C. Delete raw events after alerts are generated
D. Use tiered retention with hot, warm, and immutable archival storage

51 A SIEM detects a possible account takeover, but the account belongs to an emergency-response engineer. Which automation design best balances containment and operational risk?

Security Information and Event Management: automated response and remediation Hard
A. Require risk-based approval or step-up verification before disruptive action
B. Automatically delete the account's recent authentication history
C. Ignore all alerts involving emergency-response accounts
D. Disable the account immediately for every matching alert

52 A hunter finds a suspicious domain in DNS logs but cannot determine whether the activity was malicious. Which next pivot provides the strongest contextual enrichment?

Security Information and Event Management: threat hunting with SIEM Hard
A. Count how many times the domain appears in the dashboard
B. Block the domain before collecting additional evidence
C. Search for the domain only in firewall deny logs
D. Correlate DNS requests with endpoint processes, users, and subsequent connections

53 A SOC has frequent alert backlogs because rules generate duplicate alerts for the same incident across multiple sources. Which operational improvement most directly addresses the problem?

Security Information and Event Management: operational requirements Hard
A. Reduce the retention period for all security logs
B. Increase the number of unreviewed detection rules
C. Define deduplication, ownership, severity, escalation, and service-level procedures
D. Send every alert to all analysts simultaneously

54 A user normally accesses systems from one country during business hours but suddenly authenticates from another country using a new device and downloads an unusual volume of sensitive data. Why is UEBA more useful than a static allowlist in this case?

Security Analytics and Machine Learning in SOC: behavioral analytics and UEBA Hard
A. UEBA replaces the need for authentication controls
B. UEBA evaluates deviations across identity, device, time, location, and activity
C. UEBA detects only known malicious file hashes
D. UEBA approves every login from a previously observed country

55 A classifier achieves 99.5% accuracy on a test set where only 0.1% of events are malicious. Which conclusion is most defensible?

Security Analytics and Machine Learning in SOC: ML-based security analytics Hard
A. The model is operationally excellent
B. The model has detected nearly all attacks
C. Accuracy alone is insufficient; precision, recall, and class imbalance must be examined
D. The test set proves the model has no false positives

56 A predictive model was trained on historical data collected before a major cloud migration. After deployment, feature distributions shift substantially. What is the primary risk?

Security Analytics and Machine Learning in SOC: deployment of predictive models Hard
A. The model becomes deterministic and therefore more accurate
B. Encryption automatically corrects the predictions
C. Concept or data drift can reduce model validity
D. More storage guarantees higher recall

57 An unsupervised detector flags a large number of anomalies immediately after a company-wide shift to remote work. What is the best first response?

Security Analytics and Machine Learning in SOC: anomaly detection in SOC Hard
A. Raise the threshold until no anomalies remain
B. Validate the baseline against the operational change and retrain or segment it
C. Disable all anomaly detection permanently
D. Treat every anomaly as a confirmed incident

58 A privileged service account performs thousands of successful logins daily, making volume-based UEBA alerts noisy. Which refinement is most appropriate?

Security Analytics and Machine Learning in SOC: behavioral analytics and UEBA Hard
A. Apply the same baseline used for human employees
B. Model its expected peers, destinations, schedules, and authentication methods
C. Alert only when the account fails one password attempt
D. Exclude the service account from all monitoring

59 A SIEM distributes events by source region, but an attacker's activity spans two regions and the correlation rule runs independently in each partition. What architectural issue does this reveal?

Security Information and Event Management: distributed processing Hard
A. The event fields are necessarily over-normalized
B. The collectors are using too much compression
C. The system lacks cross-partition state or global correlation
D. The archive tier is too inexpensive

60 An automated playbook isolates an endpoint after detecting ransomware-like behavior. The endpoint may contain volatile evidence needed for investigation. Which playbook change is most appropriate?

Security Information and Event Management: automated response and remediation Hard
A. Delete suspicious files before collecting metadata
B. Perform evidence-preserving collection before or during isolation
C. Power off every endpoint in the same network segment
D. Suppress the event to avoid disrupting the user