Read raw logs, decode encoded payloads, verify log-source configuration, and correlate related events across sources. The single most important skill is distinguishing benign noise from a real multi-event attack pattern before escalating.
Start practicing
Log Management and SIEM — choose a session length
Free · No account required
Domain overview
This domain covers collecting, normalizing, correlating, and alerting on log data using SIEM tooling. GSEC questions present analyst scenarios: decoding suspicious web requests, fixing Windows Event Forwarding parsing, investigating VPN login anomalies, and preparing log sources for correlation and enrichment.
Exam objectives
Decoding URL-encoded web requests (percent-encoding like %27, %20, %3D) to spot injection attempts
Troubleshooting Windows Event Forwarding (WEF) subscriptions and SIEM parsing of Windows event logs
Correlating failed VPN authentications with a later successful login from an unusual location
Normalizing and enriching log sources so SIEM correlation rules and alerts fire correctly
Treating percent-encoded strings as harmless instead of decoding them to reveal SQL injection or traversal payloads
Assuming WEF delivers already-parsed fields; subscription and collector configuration still affect what the SIEM receives
Alerting on a single failed login or lone geo-anomaly instead of correlating multiple events into one incident
Click any question to see the full explanation and answer options, or start a focused practice session above.
An analyst notices that the SIEM is triggering an excessive number of 'False Positive' alerts related to failed login attempts. Which strategy is most effective for reducing these alerts without compromising security posture?
2Refer to the exhibit. An analyst observes the provided log output. What is the most likely security incident occurring, and what is the best immediate action?
3Which THREE of the following represent critical log sources that should be ingested into a SIEM for effective network-wide security visibility? (Choose three)
4A security analyst is tuning the SIEM to reduce noise. The current rule fires whenever a Windows event with ID 4625 (failed logon) occurs. Which modification should the analyst make to the rule to better identify a brute-force attack while reducing false positives?
5A security operations center (SOC) ingests NetFlow records into its SIEM. An analyst wants to detect potential data exfiltration over the network. Which SIEM correlation strategy is most effective for this purpose?
6A security analyst is tuning a Splunk Enterprise correlation search that detects brute-force attempts against SSH. The current search fires thousands of alerts daily because it counts every failed password event, including those from a single user who mistypes a password once. The analyst needs to reduce noise while still catching distributed brute-force attacks. Which modification should the analyst make to the correlation search?
7A security operations center (SOC) uses a SIEM to collect logs from various sources. The SOC manager wants to ensure that log data is retained for at least one year to meet regulatory requirements, but the SIEM's primary storage is expensive and limited. Which log management strategy should the SOC implement to meet the retention requirement cost-effectively?
8A SIEM administrator is troubleshooting why Windows event logs forwarded from a domain controller are not being parsed correctly. The logs are sent using the Windows Event Forwarding (WEF) subscription, but the SIEM shows raw XML instead of normalized fields. The administrator confirms that the WEF subscription is active and events are arriving. Which action should the administrator take to ensure proper parsing?
9A security analyst is investigating a potential data exfiltration incident. The SIEM has ingested firewall logs that show outbound connections, but the analyst notices that the logs do not include the number of bytes transferred. The analyst needs to correlate this with other log sources to estimate the volume of data exfiltrated. Which additional log source would provide the most direct and reliable measurement of data volume for outbound connections?
10A security analyst is investigating a potential insider threat. The SIEM has ingested logs from multiple sources, including Windows Security logs, Linux auditd, and VPN concentrators. The analyst needs to determine which user account accessed a sensitive file server at 2:00 AM. Which log source and field should the analyst query to identify the user account that initiated the file access?
11A security team is implementing a SIEM and needs to ensure that log sources are properly normalized and enriched to support effective correlation and alerting. Which TWO of the following tasks are essential for achieving this goal? (Choose two.)
12A security analyst is reviewing a SIEM alert indicating multiple failed VPN authentication attempts followed by a successful login from an unusual geographic location for the same user account. The analyst wants to determine if this is a compromised account or a legitimate user traveling. Which additional data source would best help the analyst make this determination?
13A security analyst is reviewing logs from a Linux web server that has been compromised. The analyst notices a large number of requests to a specific URL that include encoded characters such as %27, %20, and %3D. The web server logs show these requests in the access log with a 200 OK response. Which type of attack is most likely indicated by these log entries?
14A SOC uses a SIEM to monitor a fleet of Linux application servers. During an incident review, analysts discover that an attacker who obtained root on one server used the command 'shred -u -z /var/log/auth.log' after gaining access. The SIEM received no authentication events from that host for the 40-minute window in which the attacker operated, even though the agent remained online and continued forwarding other log files. Which mechanism in the log pipeline most directly explains the absence of those authentication events in the SIEM, and what is the most effective control to detect this behavior in the future?
Read raw logs, decode encoded payloads, verify log-source configuration, and correlate related events across sources. The single most important skill is distinguishing benign noise from a real multi-event attack pattern before escalating.
The Courseiva GSEC question bank contains 14 questions in the Log Management and SIEM domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Log Management and SIEM domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included