312-39 · domain
Log Management
Practise Certified SOC Analyst (312-39) Log Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Log Management questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Log Management
Log Management questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Log Management exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Log Management questions (16)
Click any question to see the full explanation, or start a practice session above.
You are configuring a syslog-ng server to receive logs from multiple network devices. To ensure that logs from different departments are stored in separate directories based on the hostname, which directive should you utilize in the destination path?
Medium2What is the primary benefit of using a centralized logging server compared to local logging?
Easy3Which THREE challenges are commonly associated with centralized log management in a large-scale enterprise?
Hard4Which TWO methods are commonly used to achieve log normalization in a modern SIEM?
Hard5A security analyst needs to ensure that sensitive log data is protected during transmission between a remote web server and the central SIEM. Which mechanism provides the highest level of security?
Medium6Which TWO log types are considered critical for forensic analysis after a network intrusion?
Easy7You are managing log rotation on a Linux-based log aggregator. Which configuration file is used by the logrotate utility to define the retention and compression settings for log files?
Medium8Which THREE items are essential components of a robust log management policy?
Medium9Which THREE factors should be considered when determining the log retention period in a SOC environment?
Medium10When implementing a centralized logging architecture, which protocol is preferred for log transmission to ensure delivery confirmation between the collector and the aggregator?
Easy11You are defining log retention policies. According to general compliance standards like PCI-DSS, what is the primary requirement for log retention?
Easy12When parsing unstructured logs into a structured format (JSON), which technique is most effective for mapping log fields to SIEM taxonomy?
Medium13Which log management component is responsible for receiving log data from various network nodes and normalizing the format before storage?
Easy14You want to implement log integrity monitoring to ensure that logs are not tampered with after they are written. Which method is most robust?
Medium15You notice that your SIEM is not receiving logs from a Windows domain controller. After verifying network connectivity, you check the Windows Event Forwarding (WEF) subscription status. Which command is used to check the status of active subscriptions on the local machine?
Hard16An organization is migrating to a cloud-native logging architecture using AWS CloudWatch. You need to forward logs from an on-premises server to CloudWatch. Which agent is the correct choice to facilitate this stream?
HardOther domains
All 312-39 exam domains
Frequently asked questions
- What does the Log Management domain cover on the 312-39 exam?
- Log Management questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 16 Log Management questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Log Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.