Unit 3: Endpoint, SIEM, and Security Analytics - Subjective Questions

INT244 — Securing Computing Systems • Practice Questions with Detailed Answers

20 questions

1

Define Endpoint Detection and Response (EDR). Explain its main components and describe how EDR supports threat hunting.

2

Explain the major stages of malware analysis and reverse engineering. How do static and dynamic analysis complement each other?

3

Explain data-focused and asset-focused risk models used in endpoint analysis. Compare their objectives and give suitable examples.

4

Describe the fundamental principles of endpoint security and explain how they reduce the attack surface.

5

Define Security Information and Event Management (SIEM). Explain its basic architecture and core functions.

6

Explain distributed processing in SIEM systems. Why is it important for large-scale security monitoring?

7

Explain how SIEM systems accelerate threat hunting. Include the role of normalization, correlation, search, and enrichment.

8

Describe how SIEM supports regulatory reporting. What controls are necessary to ensure that reports are reliable and auditable?

9

Explain the infrastructure management requirements of a SIEM deployment.

10

Develop a SIEM log retention strategy for an organization. Discuss the technical, operational, legal, and financial factors that should be considered.

11

Explain automated response and remediation in SIEM. Discuss its advantages, risks, and safeguards.

12

Describe a systematic process for threat hunting with SIEM.

13

Explain the operational requirements for an effective SIEM program.

14

Define behavioral analytics and User and Entity Behavior Analytics (UEBA). Explain how they identify suspicious activity.

15

Explain the role of machine learning in security analytics. Compare supervised, unsupervised, and semi-supervised approaches.

16

Describe the process of deploying a predictive security model in a Security Operations Center.

17

Explain anomaly detection in a SOC. Distinguish between point, contextual, and collective anomalies with examples.

18

Compare EDR and SIEM in terms of data collection, detection scope, investigation, and response capabilities. Explain why they are commonly integrated.

19

Derive a simple risk-prioritization model for endpoint incidents using likelihood, asset criticality, data sensitivity, and control effectiveness. Explain how the model can guide response.

20

Explain how distributed SIEM processing can be designed for high availability and disaster recovery.