GSEC · domain
Log Management and SIEM
This domain covers collecting, normalizing, correlating, and alerting on log data using SIEM tooling. GSEC questions present analyst scenarios: decoding suspicious web requests, fixing Windows Event Forwarding parsing, investigating VPN login anomalies, and preparing log sources for correlation and enrichment.
Focused practice
Practice Log Management and SIEM questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Log Management and SIEM
Read raw logs, decode encoded payloads, verify log-source configuration, and correlate related events across sources. The single most important skill is distinguishing benign noise from a real multi-event attack pattern before escalating.
Decoding URL-encoded web requests (percent-encoding like %27, %20, %3D) to spot injection attempts
Troubleshooting Windows Event Forwarding (WEF) subscriptions and SIEM parsing of Windows event logs
Correlating failed VPN authentications with a later successful login from an unusual location
Normalizing and enriching log sources so SIEM correlation rules and alerts fire correctly
Watch out for
Common Log Management and SIEM exam traps
- ▸Treating percent-encoded strings as harmless instead of decoding them to reveal SQL injection or traversal payloads
- ▸Assuming WEF delivers already-parsed fields; subscription and collector configuration still affect what the SIEM receives
- ▸Alerting on a single failed login or lone geo-anomaly instead of correlating multiple events into one incident
Question index
All Log Management and SIEM questions (14)
Click any question to see the full explanation, or start a practice session above.
A security analyst is tuning the SIEM to reduce noise. The current rule fires whenever a Windows event with ID 4625 (failed logon) occurs. Which modification should the analyst make to the rule to better identify a brute-force attack while reducing false positives?
Medium2An analyst notices that the SIEM is triggering an excessive number of 'False Positive' alerts related to failed login attempts. Which strategy is most effective for reducing these alerts without compromising security posture?
Medium3A SOC uses a SIEM to monitor a fleet of Linux application servers. During an incident review, analysts discover that an attacker who obtained root on one server used the command 'shred -u -z /var/log/auth.log' after gaining access. The SIEM received no authentication events from that host for the 40-minute window in which the attacker operated, even though the agent remained online and continued forwarding other log files. Which mechanism in the log pipeline most directly explains the absence of those authentication events in the SIEM, and what is the most effective control to detect this behavior in the future?
Hard4Which THREE of the following represent critical log sources that should be ingested into a SIEM for effective network-wide security visibility? (Choose three)
Medium5A security analyst is investigating a potential data exfiltration incident. The SIEM has ingested firewall logs that show outbound connections, but the analyst notices that the logs do not include the number of bytes transferred. The analyst needs to correlate this with other log sources to estimate the volume of data exfiltrated. Which additional log source would provide the most direct and reliable measurement of data volume for outbound connections?
Hard6Refer to the exhibit. An analyst observes the provided log output. What is the most likely security incident occurring, and what is the best immediate action?
Hard7A security operations center (SOC) uses a SIEM to collect logs from various sources. The SOC manager wants to ensure that log data is retained for at least one year to meet regulatory requirements, but the SIEM's primary storage is expensive and limited. Which log management strategy should the SOC implement to meet the retention requirement cost-effectively?
Easy8A security operations center (SOC) ingests NetFlow records into its SIEM. An analyst wants to detect potential data exfiltration over the network. Which SIEM correlation strategy is most effective for this purpose?
Hard9A security analyst is investigating a potential insider threat. The SIEM has ingested logs from multiple sources, including Windows Security logs, Linux auditd, and VPN concentrators. The analyst needs to determine which user account accessed a sensitive file server at 2:00 AM. Which log source and field should the analyst query to identify the user account that initiated the file access?
Medium10A security analyst is tuning a Splunk Enterprise correlation search that detects brute-force attempts against SSH. The current search fires thousands of alerts daily because it counts every failed password event, including those from a single user who mistypes a password once. The analyst needs to reduce noise while still catching distributed brute-force attacks. Which modification should the analyst make to the correlation search?
Medium11A security analyst is reviewing logs from a Linux web server that has been compromised. The analyst notices a large number of requests to a specific URL that include encoded characters such as %27, %20, and %3D. The web server logs show these requests in the access log with a 200 OK response. Which type of attack is most likely indicated by these log entries?
Easy12A SIEM administrator is troubleshooting why Windows event logs forwarded from a domain controller are not being parsed correctly. The logs are sent using the Windows Event Forwarding (WEF) subscription, but the SIEM shows raw XML instead of normalized fields. The administrator confirms that the WEF subscription is active and events are arriving. Which action should the administrator take to ensure proper parsing?
Hard13A security analyst is reviewing a SIEM alert indicating multiple failed VPN authentication attempts followed by a successful login from an unusual geographic location for the same user account. The analyst wants to determine if this is a compromised account or a legitimate user traveling. Which additional data source would best help the analyst make this determination?
Hard14A security team is implementing a SIEM and needs to ensure that log sources are properly normalized and enriched to support effective correlation and alerting. Which TWO of the following tasks are essential for achieving this goal? (Choose two.)
MediumOther domains
All GSEC exam domains
Frequently asked questions
- What does the Log Management and SIEM domain cover on the GSEC exam?
- Read raw logs, decode encoded payloads, verify log-source configuration, and correlate related events across sources. The single most important skill is distinguishing benign noise from a real multi-event attack pattern before escalating.
- How many questions are in this domain?
- This page lists all 14 Log Management and SIEM questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Log Management and SIEM questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.