Practice 312-39 Log Management questions with full explanations on every answer.
Start practicing
Log Management — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are defining log retention policies. According to general compliance standards like PCI-DSS, what is the primary requirement for log retention?
2When implementing a centralized logging architecture, which protocol is preferred for log transmission to ensure delivery confirmation between the collector and the aggregator?
3An organization is migrating to a cloud-native logging architecture using AWS CloudWatch. You need to forward logs from an on-premises server to CloudWatch. Which agent is the correct choice to facilitate this stream?
4A security analyst needs to ensure that sensitive log data is protected during transmission between a remote web server and the central SIEM. Which mechanism provides the highest level of security?
5You are configuring a syslog-ng server to receive logs from multiple network devices. To ensure that logs from different departments are stored in separate directories based on the hostname, which directive should you utilize in the destination path?
6You are managing log rotation on a Linux-based log aggregator. Which configuration file is used by the logrotate utility to define the retention and compression settings for log files?
7When parsing unstructured logs into a structured format (JSON), which technique is most effective for mapping log fields to SIEM taxonomy?
8Which log management component is responsible for receiving log data from various network nodes and normalizing the format before storage?
9Which THREE items are essential components of a robust log management policy?
10You notice that your SIEM is not receiving logs from a Windows domain controller. After verifying network connectivity, you check the Windows Event Forwarding (WEF) subscription status. Which command is used to check the status of active subscriptions on the local machine?
11You want to implement log integrity monitoring to ensure that logs are not tampered with after they are written. Which method is most robust?
12What is the primary benefit of using a centralized logging server compared to local logging?
13Which TWO log types are considered critical for forensic analysis after a network intrusion?
14Which TWO methods are commonly used to achieve log normalization in a modern SIEM?
15Which THREE factors should be considered when determining the log retention period in a SOC environment?
16Which THREE challenges are commonly associated with centralized log management in a large-scale enterprise?
The Log Management domain covers the key concepts tested in this area of the 312-39 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-39 domains — no account required.
The Courseiva 312-39 question bank contains 16 questions in the Log Management domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Log Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included