Courseiva

CCNA Log Management And Siem Questions

14 questions · Log Management And Siem topic · All types, answers revealed

1
MCQmedium

A security analyst is tuning the SIEM to reduce noise. The current rule fires whenever a Windows event with ID 4625 (failed logon) occurs. Which modification should the analyst make to the rule to better identify a brute-force attack while reducing false positives?

A.Set the rule to alert only when event ID 4625 occurs outside of business hours.
B.Add a filter to exclude all failed logon events from privileged accounts.
C.Configure the rule to trigger only when event ID 4625 is followed by event ID 4624 (successful logon) from the same user within 1 minute.
D.Change the rule to trigger only when the same source IP generates more than 10 failed logons within 5 minutes.
AnswerD

Threshold-based correlation on source IP and time window is a standard SIEM technique to distinguish brute-force attempts from isolated user errors. Ten failures in five minutes from one source exceeds normal human error rates and indicates automated guessing, while ignoring scattered single failures that are typical of mistyped passwords.

Why this answer

Brute-force attacks are characterized by a high volume of failed authentication attempts from a single source in a short period. A threshold-based correlation rule that counts failures per source IP within a time window effectively separates automated attacks from occasional user mistypes, reducing false positives while maintaining detection fidelity.

Exam trap

The trap here is assuming that any filter based on time or account type will reduce false positives without considering that attackers can mimic normal patterns and that high-risk accounts should never be excluded.

2
MCQmedium

An analyst notices that the SIEM is triggering an excessive number of 'False Positive' alerts related to failed login attempts. Which strategy is most effective for reducing these alerts without compromising security posture?

A.Disable all failed login logging on domain controllers to save SIEM storage.
B.Increase the severity level of all login failure logs to 'Critical'.
C.Implement a threshold-based correlation rule to alert only after five failed attempts within one minute.
D.Archive all failed login logs to cold storage immediately upon ingestion.
AnswerC

Threshold-based alerting filters out transient, single-instance failures caused by mistyped passwords or minor sync issues. By requiring multiple failures in a short duration, the system ignores common user errors while still catching automated brute-force attacks, successfully balancing signal fidelity with the need for continuous security monitoring and oversight.

Why this answer

Tuning the SIEM to filter noise is critical for preventing analyst fatigue and ensuring high-fidelity alerts remain visible. By creating suppression rules for known service account behavior or implementing threshold-based alerts, analysts can focus on genuine threats. This process is essential for maintaining a healthy SIEM environment where security teams can respond efficiently to legitimate incidents rather than chasing benign log noise generated by standard system maintenance tasks.

Exam trap

Candidates suggest disabling logging entirely or increasing log retention periods, which either blinds the security team or fails to reduce active alert noise.

3
MCQhard

A SOC uses a SIEM to monitor a fleet of Linux application servers. During an incident review, analysts discover that an attacker who obtained root on one server used the command 'shred -u -z /var/log/auth.log' after gaining access. The SIEM received no authentication events from that host for the 40-minute window in which the attacker operated, even though the agent remained online and continued forwarding other log files. Which mechanism in the log pipeline most directly explains the absence of those authentication events in the SIEM, and what is the most effective control to detect this behavior in the future?

A.The attacker changed the file permissions to 000 so the agent could no longer read it; enforce file integrity monitoring with auditd watching /var/log/auth.log for permission changes.
B.The SIEM's correlation engine suppressed duplicate events because the attacker's session generated repeated identical authentication failures; add a threshold rule instead of forwarding changes.
C.The agent reads log files by inode and drops the file handle when the inode is unlinked; enable remote syslog forwarding to a write-only collector so events leave the host before local deletion.
D.The attacker exploited a vulnerability in the SIEM agent to stop the service; redeploy the agent with a signed configuration and enable mutual TLS to the SIEM endpoint.
AnswerC

A file-following agent such as rsyslog's imfile or a Filebeat harvester tracks an inode and keeps the descriptor open while the file exists. Once 'shred -u' unlinks and overwrites the file, the agent's handle is invalidated and subsequent writes never arrive. Forwarding authentication events off-host in real time with rsyslog or journald to a remote collector removes the local file as a single point of failure, so the attacker cannot suppress events already transmitted.

Why this answer

Local log files are only as trustworthy as the host that writes them. An agent that tails a file by inode loses its handle when the file is unlinked, so events written after 'shred -u' never reach the SIEM. Sending authentication and audit events to a remote collector in real time means the record already exists off-host before an attacker can destroy it, which is why real-time forwarding is the most effective control for this scenario.

Exam trap

The trap here is assuming that a still-running agent guarantees complete log delivery, when file-following collectors actually depend on the underlying inode remaining intact.

4
MCQmedium

Which THREE of the following represent critical log sources that should be ingested into a SIEM for effective network-wide security visibility? (Choose three)

A.Firewall logs
B.Local printer spooler temporary files
C.Authentication (Active Directory) logs
D.Antivirus/EDR alerts
E.Office document metadata templates
AnswerA, C, D

Firewall logs document allowed and denied traffic at network boundaries. They are essential for identifying reconnaissance, data exfiltration, and communication with known malicious command-and-control servers. Analyzing these logs helps security teams understand how traffic flows through the perimeter and identify potential entry points for attackers or internal threats.

Why this answer

Effective SIEM visibility requires a diverse set of data sources to correlate activities across the infrastructure. Combining endpoint, network, and identity logs allows for comprehensive monitoring. These sources provide the raw telemetry necessary for detecting lateral movement, command-and-control communication, and unauthorized privilege escalation.

Without this breadth of information, security teams are likely to miss the early indicators of a sophisticated attack transitioning through different segments of the enterprise network.

Exam trap

Candidates often include 'physical access logs' or 'printer logs'. While potentially useful, these are not high-priority security telemetry compared to identity, network, and endpoint alerts.

5
MCQhard

A security analyst is investigating a potential data exfiltration incident. The SIEM has ingested firewall logs that show outbound connections, but the analyst notices that the logs do not include the number of bytes transferred. The analyst needs to correlate this with other log sources to estimate the volume of data exfiltrated. Which additional log source would provide the most direct and reliable measurement of data volume for outbound connections?

A.NetFlow records from core routers and switches.
B.DNS server query logs.
C.Windows Security event logs from the source host.
D.Antivirus application logs from the endpoint.
AnswerA

NetFlow records include byte and packet counts for each flow, providing a direct measurement of data volume for outbound connections. They are generated by network devices and can be correlated with firewall logs by source/destination IP, port, and timestamp. This allows the analyst to estimate exfiltration volume accurately. NetFlow is widely supported and can be exported to the SIEM, making it the most reliable source for volume data in this scenario.

Why this answer

NetFlow provides byte and packet counts per flow, directly measuring data volume for outbound connections. Firewall logs often lack this detail, so NetFlow is the best additional source to quantify exfiltration. It can be correlated by IP, port, and time to estimate how much data left the network, making it the most direct and reliable choice.

Exam trap

The trap here is assuming that host-based logs or DNS logs contain byte counts for network connections, when only flow-based sources like NetFlow provide that level of detail.

6
MCQhard

Refer to the exhibit. An analyst observes the provided log output. What is the most likely security incident occurring, and what is the best immediate action?

A.Hardware failure; replace the server network interface card immediately.
B.Brute-force attack; investigate the source IP and block it if unauthorized.
C.Network congestion; increase the logging frequency of the server.
D.User error; reset the user's password to clear the event logs.
AnswerB

The rapid cadence of failed attempts from a single source strongly suggests an automated brute-force attack. Investigating the source IP allows the analyst to verify if the machine is a known asset or an unauthorized intruder, and blocking it is the correct containment strategy to protect the server.

Why this answer

The exhibit shows a rapid sequence of failed login attempts from a single internal IP address, which is indicative of a brute-force or credential-stuffing attack. Security professionals must identify this pattern quickly to prevent account compromise. The standard response involves investigating the source IP for malicious intent and blocking the traffic at the network perimeter or host level to mitigate the risk of unauthorized access to the server.

Exam trap

Candidates often jump to the conclusion of a DoS attack rather than a brute-force attack, or they suggest overly aggressive actions like shutting down the entire server instead of blocking the IP.

7
MCQeasy

A security operations center (SOC) uses a SIEM to collect logs from various sources. The SOC manager wants to ensure that log data is retained for at least one year to meet regulatory requirements, but the SIEM's primary storage is expensive and limited. Which log management strategy should the SOC implement to meet the retention requirement cost-effectively?

A.Configure the SIEM to compress and archive older logs to a secondary storage tier, such as a network-attached storage (NAS) or cloud object storage, after a defined period.
B.Reduce the log retention period to 30 days and rely on the original log sources to retain their own logs for one year.
C.Increase the SIEM's primary storage capacity by adding more high-performance disks to accommodate one year of logs.
D.Disable logging for low-priority sources and keep only high-priority logs for one year on primary storage.
AnswerA

Archiving older logs to cheaper secondary storage is a standard cost-effective approach for long-term retention. The SIEM keeps recent, frequently queried data on expensive primary storage, while older logs are moved to a lower-cost tier. This meets the one-year retention requirement without overprovisioning primary storage. It also allows retrieval for investigations or compliance audits, though search performance on archived data may be slower.

Why this answer

The most cost-effective way to meet long-term retention is to tier storage: keep recent logs on fast, expensive primary storage and archive older logs to cheaper secondary storage. This balances performance for active investigations with compliance retention, avoiding unnecessary primary storage expansion or risky reliance on source systems.

Exam trap

The trap here is assuming that all logs must remain on primary SIEM storage for the entire retention period, which leads to unnecessary cost and scalability issues.

8
MCQhard

A security operations center (SOC) ingests NetFlow records into its SIEM. An analyst wants to detect potential data exfiltration over the network. Which SIEM correlation strategy is most effective for this purpose?

A.Alert when any host initiates a connection to a country that is not on an approved list.
B.Correlate outbound traffic volume with destination IP reputation and unusual port usage, and alert on deviations from the host's historical baseline.
C.Alert when any internal host sends more than 1 GB of data to an external IP address within an hour.
D.Monitor for DNS queries to known command-and-control domains and alert on any match.
AnswerB

This strategy combines multiple weak indicators (volume, destination reputation, port) and behavioral baselining to increase confidence. Exfiltration often involves transfers to unknown or low-reputation IPs on non-standard ports, and volume that is anomalous for that specific host. Correlating these factors reduces false positives and catches stealthy exfiltration that avoids simple thresholds.

Why this answer

Data exfiltration detection benefits from behavioral baselining and multi-factor correlation. By learning each host's normal outbound traffic patterns and combining volume anomalies with destination reputation and port usage, the SIEM can flag suspicious transfers that would be missed by static thresholds or country blocks alone.

Exam trap

The trap here is focusing on a single indicator such as volume or geography, when effective exfiltration detection requires correlating multiple contextual factors and baselining normal behavior.

9
MCQmedium

A security analyst is investigating a potential insider threat. The SIEM has ingested logs from multiple sources, including Windows Security logs, Linux auditd, and VPN concentrators. The analyst needs to determine which user account accessed a sensitive file server at 2:00 AM. Which log source and field should the analyst query to identify the user account that initiated the file access?

A.VPN concentrator logs with the UserName field and the AssignedIP field.
B.Linux auditd logs with the key field set to "file_access" and the uid field.
C.Windows Security Event ID 4663 (An attempt was made to access an object) with the SubjectUserName field.
D.Windows Security Event ID 4624 (An account was successfully logged on) with the TargetUserName field.
AnswerC

Event ID 4663 is generated when an object (like a file) is accessed, provided object access auditing is enabled. The SubjectUserName field identifies the account that attempted the access. By filtering for the file server's object name and the timestamp, the analyst can pinpoint the user. This event is specifically designed for file access auditing, making it the most direct source for this scenario.

Why this answer

To identify the user account that accessed a sensitive file, the analyst should look for object access auditing events. Windows Security Event ID 4663 is generated when an object is accessed and includes the SubjectUserName, which identifies the account. Filtering by the file server and timestamp yields the specific user.

Other log sources either do not record file-level access or provide only indirect information.

Exam trap

The trap here is confusing logon events (4624) with object access events (4663), leading to the wrong event ID for file access auditing.

10
MCQmedium

A security analyst is tuning a Splunk Enterprise correlation search that detects brute-force attempts against SSH. The current search fires thousands of alerts daily because it counts every failed password event, including those from a single user who mistypes a password once. The analyst needs to reduce noise while still catching distributed brute-force attacks. Which modification should the analyst make to the correlation search?

A.Add a threshold condition that triggers only when more than 10 failed logins occur from the same source IP within 5 minutes.
B.Correlate failed logins across multiple source IPs by counting distinct source IPs per target account over a longer window, and trigger when the distinct count exceeds a threshold.
C.Increase the search time window to 24 hours and lower the alert threshold to 5 failed logins per user.
D.Filter out all failed password events for service accounts and only alert on failed logins for interactive user accounts.
AnswerB

This approach directly addresses distributed brute-force attacks, where many source IPs each try a few passwords against the same account. By counting distinct source IPs per target account over a longer window, the search detects the attack pattern while ignoring isolated mistyped passwords from a single user. It reduces false positives because a single user typically fails from one or two IPs, not many, and it still catches the distributed behavior.

Why this answer

Distributed brute-force attacks spread login attempts across many source IPs to evade per-IP thresholds. The effective detection method is to correlate failed logins by target account and count distinct source IPs over a longer period. This catches the attack while ignoring a single user's occasional mistyped password, reducing false positives without missing the distributed pattern.

Exam trap

The trap here is assuming that a simple per-source-IP threshold will catch all brute-force attacks, when distributed attacks deliberately use many IPs to stay under such thresholds.

11
MCQeasy

A security analyst is reviewing logs from a Linux web server that has been compromised. The analyst notices a large number of requests to a specific URL that include encoded characters such as %27, %20, and %3D. The web server logs show these requests in the access log with a 200 OK response. Which type of attack is most likely indicated by these log entries?

A.Cross-site scripting (XSS)
B.Directory traversal
C.Command injection
D.SQL injection
AnswerD

SQL injection attempts often use encoded characters like %27 (single quote) to break out of SQL queries, %20 (space) to separate keywords, and %3D (equals) for comparisons. The fact that the server returned 200 OK suggests the requests were successful, possibly indicating a vulnerable application. These encoded characters are classic indicators of SQL injection probing, especially when repeated in URL parameters.

Why this answer

The encoded characters %27 (single quote), %20 (space), and %3D (equals) are commonly used in SQL injection attempts to manipulate SQL queries. The single quote is used to terminate strings, spaces separate SQL keywords, and equals signs are used in comparisons. The successful 200 OK responses suggest the application may be vulnerable.

Other attack types would exhibit different patterns in the logs.

Exam trap

The trap here is assuming that any encoded characters in URLs indicate XSS or directory traversal, when the specific set of characters points to SQL injection.

12
MCQhard

A SIEM administrator is troubleshooting why Windows event logs forwarded from a domain controller are not being parsed correctly. The logs are sent using the Windows Event Forwarding (WEF) subscription, but the SIEM shows raw XML instead of normalized fields. The administrator confirms that the WEF subscription is active and events are arriving. Which action should the administrator take to ensure proper parsing?

A.Install a SIEM agent on the domain controller to read the event logs directly and forward them in a normalized format.
B.Configure the SIEM to use the Windows Event Log collector with the correct channel names and enable XML parsing.
C.Modify the WEF subscription to forward events in JSON format instead of XML.
D.Create a custom parser in the SIEM that extracts fields from the XML structure of the WEF events.
AnswerD

When WEF forwards events, they are encapsulated in XML. If the SIEM's default Windows parser expects a different format (e.g., EVTX or JSON), it will fail to extract fields, resulting in raw XML. Creating a custom parser that understands the WEF XML schema and maps fields like EventID, Computer, and SubjectUserName to the SIEM's normalized schema will enable proper parsing and correlation.

Why this answer

WEF forwards events in XML format. If the SIEM's collector is not configured to parse that XML, it stores raw XML and fields are not normalized. The administrator should create a custom parser that extracts relevant fields from the WEF XML schema and maps them to the SIEM's data model.

Other options either do not address the parsing issue or are technically infeasible.

Exam trap

The trap here is assuming that enabling generic XML parsing will automatically map fields correctly, when a custom parser tailored to the WEF schema is needed.

13
MCQhard

A security analyst is reviewing a SIEM alert indicating multiple failed VPN authentication attempts followed by a successful login from an unusual geographic location for the same user account. The analyst wants to determine if this is a compromised account or a legitimate user traveling. Which additional data source would best help the analyst make this determination?

A.Firewall logs showing outbound connections from the VPN-assigned IP address.
B.HR system records of approved travel requests for the user.
C.VPN concentrator logs showing the assigned IP address and session duration for the successful login.
D.Endpoint detection and response (EDR) logs from the user's laptop.
AnswerB

HR travel records can confirm whether the user is authorized to be in that geographic location, directly addressing the question of legitimate travel. If a travel request exists for the same timeframe, it supports the benign explanation. If not, it increases suspicion of compromise. This source provides authoritative business context that is not available in technical logs, making it the best additional data source for this determination.

Why this answer

The key question is whether the login from an unusual location is legitimate travel. HR travel records provide authoritative confirmation of approved travel, directly addressing that question. Technical logs like VPN, EDR, or firewall can show activity but do not confirm the business reason for the location.

HR data is the most direct source to distinguish compromise from legitimate travel.

Exam trap

The trap here is focusing solely on technical logs to determine legitimacy, when business context such as HR travel records is often the most direct evidence for authorized travel.

14
Multi-Selectmedium

A security team is implementing a SIEM and needs to ensure that log sources are properly normalized and enriched to support effective correlation and alerting. Which TWO of the following tasks are essential for achieving this goal? (Choose two.)

Select 2 answers
A.Enriching events with contextual data, such as asset criticality, user identity, and geolocation, from external sources.
B.Configuring the SIEM to drop logs that do not match the expected format to reduce noise.
C.Mapping vendor-specific log fields to a common schema, such as the Splunk Common Information Model (CIM).
D.Storing all raw logs indefinitely in their original format without normalization.
E.Increasing the SIEM's indexing speed by disabling timestamp recognition on all logs.
AnswersA, C

Enrichment adds context to raw events, enabling more accurate correlation and prioritization. For example, knowing that a server is critical or that a user is a privileged administrator helps analysts assess the severity of an alert. Geolocation can highlight impossible travel. This task is essential for effective alerting because it reduces false positives and helps focus on high-risk activities. It complements normalization by adding business-relevant metadata.

Why this answer

Normalization and enrichment are critical for SIEM effectiveness. Mapping fields to a common schema like the Splunk CIM ensures consistent field names for correlation. Enriching with context such as asset criticality and geolocation improves alert accuracy and prioritization.

These two tasks together enable the SIEM to correlate events across diverse sources and generate meaningful alerts.

Exam trap

The trap here is thinking that dropping non-conforming logs or storing raw logs indefinitely is part of normalization and enrichment, when those actions actually hinder effective correlation.

Ready to test yourself?

Try a timed practice session using only Log Management And Siem questions.