Courseiva

312-39 · topic practice

Log Management practice questions

Practise Certified SOC Analyst (312-39) Log Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
17 questionsDomain: Log Management

What the exam tests

What to know about Log Management

Log Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Log Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Log Management questions

17 questions · select your answer, then reveal the explanation

You are troubleshooting a performance bottleneck in an ELK Stack deployment. Logstash is dropping events due to backpressure. Which configuration parameter in the Logstash pipeline file is best suited to manage the queue size and prevent memory overflow?

You are defining log retention policies. According to general compliance standards like PCI-DSS, what is the primary requirement for log retention?

When implementing a centralized logging architecture, which protocol is preferred for log transmission to ensure delivery confirmation between the collector and the aggregator?

An organization is migrating to a cloud-native logging architecture using AWS CloudWatch. You need to forward logs from an on-premises server to CloudWatch. Which agent is the correct choice to facilitate this stream?

Question 5mediummultiple choice
Read the full Log Management explanation →

A security analyst needs to ensure that sensitive log data is protected during transmission between a remote web server and the central SIEM. Which mechanism provides the highest level of security?

You are configuring a syslog-ng server to receive logs from multiple network devices. To ensure that logs from different departments are stored in separate directories based on the hostname, which directive should you utilize in the destination path?

Question 7mediummultiple choice
Read the full Log Management explanation →

You are managing log rotation on a Linux-based log aggregator. Which configuration file is used by the logrotate utility to define the retention and compression settings for log files?

Question 8mediummultiple choice
Read the full Log Management explanation →

When parsing unstructured logs into a structured format (JSON), which technique is most effective for mapping log fields to SIEM taxonomy?

Which log management component is responsible for receiving log data from various network nodes and normalizing the format before storage?

Which THREE items are essential components of a robust log management policy?

Question 11hardmultiple choice
Read the full Log Management explanation →

You notice that your SIEM is not receiving logs from a Windows domain controller. After verifying network connectivity, you check the Windows Event Forwarding (WEF) subscription status. Which command is used to check the status of active subscriptions on the local machine?

Question 12mediummultiple choice
Read the full Log Management explanation →

You want to implement log integrity monitoring to ensure that logs are not tampered with after they are written. Which method is most robust?

Question 13easymultiple choice
Read the full Log Management explanation →

What is the primary benefit of using a centralized logging server compared to local logging?

Which TWO log types are considered critical for forensic analysis after a network intrusion?

Which TWO methods are commonly used to achieve log normalization in a modern SIEM?

Which THREE factors should be considered when determining the log retention period in a SOC environment?

Which THREE challenges are commonly associated with centralized log management in a large-scale enterprise?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Log Management sessions

Start a Log Management only practice session

Every question in these sessions is drawn from the Log Management domain — nothing else.

Related practice questions

Related 312-39 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 312-39 exam test about Log Management?
Log Management questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Log Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Log Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 312-39 topics?
Use the topic links above to move to related areas, or go back to the 312-39 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 312-39 exam covers. They are not copied from any real exam or dump site.