Courseiva

GSEC · topic practice

Log Management and SIEM practice questions

This domain covers collecting, normalizing, correlating, and alerting on log data using SIEM tooling. GSEC questions present analyst scenarios: decoding suspicious web requests, fixing Windows Event Forwarding parsing, investigating VPN login anomalies, and preparing log sources for correlation and enrichment.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Log Management and SIEM

What the exam tests

What to know about Log Management and SIEM

Read raw logs, decode encoded payloads, verify log-source configuration, and correlate related events across sources. The single most important skill is distinguishing benign noise from a real multi-event attack pattern before escalating.

Decoding URL-encoded web requests (percent-encoding like %27, %20, %3D) to spot injection attempts

Troubleshooting Windows Event Forwarding (WEF) subscriptions and SIEM parsing of Windows event logs

Correlating failed VPN authentications with a later successful login from an unusual location

Normalizing and enriching log sources so SIEM correlation rules and alerts fire correctly

Watch out for

Common Log Management and SIEM exam traps

  • ▸Treating percent-encoded strings as harmless instead of decoding them to reveal SQL injection or traversal payloads
  • ▸Assuming WEF delivers already-parsed fields; subscription and collector configuration still affect what the SIEM receives
  • ▸Alerting on a single failed login or lone geo-anomaly instead of correlating multiple events into one incident

Practice set

Log Management and SIEM questions

20 questions · select your answer, then reveal the explanation

A security analyst is tasked with creating a SIEM correlation rule to detect potential credential stuffing attacks against an enterprise web application. Which behavioral pattern provides the most reliable indicator for this specific threat vector while minimizing false positives from legitimate users?

Refer to the exhibit. An analyst reviews the parsed Windows security event JSON payload forwarded to the SIEM. Based on the event attributes, what specific activity does this log entry represent?

Exhibit

{
  "timestamp": "2023-10-27T14:32:10Z",
  "event_id": 4624,
  "logon_type": 3,
  "source_ip": "192.168.100.50",
  "target_user": "jsmith",
  "authentication_package": "NTLM",
  "failure_reason": "N/A"
}

Refer to the exhibit. An auditor reviews the Linux authentication logs for suspicious administrative activity. What security concern is highlighted by the chronological sequence of these two log entries?

Exhibit

Jun 14 08:12:35 authsrv sshd[4521]: Accepted publickey for root from 10.0.0.15 port 54321 ssh2: RSA SHA256:abc123xyz
Jun 14 08:14:02 authsrv sudo[4810]:   jsmith : TTY=pts/0 ; PWD=/home/jsmith ; USER=root ; COMMAND=/bin/bash

A security team needs to ensure log integrity for compliance purposes. Which log management practice provides the strongest assurance that log data has not been tampered with after ingestion?

Which TWO of the following are primary benefits of implementing a centralized log management (CLM) architecture? (Choose two)

A security operations center (SOC) receives a SIEM alert for a suspected data exfiltration. The analyst wants to correlate outbound network flows with the associated endpoint process information to determine which application initiated the transfer. The environment collects logs from a Zeek network sensor and Windows Sysmon. Which log source and field combination should the analyst use to correlate the flow to the process?

A security team is designing a SIEM correlation rule to detect potential lateral movement using Windows Remote Desktop Protocol (RDP). They want to alert when a user account successfully authenticates to multiple distinct hosts via RDP within a short time window. Which TWO log sources and events should be used to build this correlation? (Choose two.)

An analyst notices that the SIEM is triggering an excessive number of 'False Positive' alerts related to failed login attempts. Which strategy is most effective for reducing these alerts without compromising security posture?

Refer to the exhibit. An analyst observes the provided log output. What is the most likely security incident occurring, and what is the best immediate action?

Exhibit

2023-10-12T14:22:01Z [WARN] Failed login from 192.168.1.55 on host SRV-01
2023-10-12T14:22:02Z [WARN] Failed login from 192.168.1.55 on host SRV-01
2023-10-12T14:22:03Z [WARN] Failed login from 192.168.1.55 on host SRV-01
2023-10-12T14:22:04Z [WARN] Failed login from 192.168.1.55 on host SRV-01

Which THREE of the following represent critical log sources that should be ingested into a SIEM for effective network-wide security visibility? (Choose three)

A security analyst is tuning the SIEM to reduce noise. The current rule fires whenever a Windows event with ID 4625 (failed logon) occurs. Which modification should the analyst make to the rule to better identify a brute-force attack while reducing false positives?

A security operations center (SOC) ingests NetFlow records into its SIEM. An analyst wants to detect potential data exfiltration over the network. Which SIEM correlation strategy is most effective for this purpose?

A security analyst is tuning a Splunk Enterprise correlation search that detects brute-force attempts against SSH. The current search fires thousands of alerts daily because it counts every failed password event, including those from a single user who mistypes a password once. The analyst needs to reduce noise while still catching distributed brute-force attacks. Which modification should the analyst make to the correlation search?

A security operations center (SOC) uses a SIEM to collect logs from various sources. The SOC manager wants to ensure that log data is retained for at least one year to meet regulatory requirements, but the SIEM's primary storage is expensive and limited. Which log management strategy should the SOC implement to meet the retention requirement cost-effectively?

A SIEM administrator is troubleshooting why Windows event logs forwarded from a domain controller are not being parsed correctly. The logs are sent using the Windows Event Forwarding (WEF) subscription, but the SIEM shows raw XML instead of normalized fields. The administrator confirms that the WEF subscription is active and events are arriving. Which action should the administrator take to ensure proper parsing?

A security analyst is investigating a potential data exfiltration incident. The SIEM has ingested firewall logs that show outbound connections, but the analyst notices that the logs do not include the number of bytes transferred. The analyst needs to correlate this with other log sources to estimate the volume of data exfiltrated. Which additional log source would provide the most direct and reliable measurement of data volume for outbound connections?

Question 17mediummultiple choice
Read the full VPN explanation →

A security analyst is investigating a potential insider threat. The SIEM has ingested logs from multiple sources, including Windows Security logs, Linux auditd, and VPN concentrators. The analyst needs to determine which user account accessed a sensitive file server at 2:00 AM. Which log source and field should the analyst query to identify the user account that initiated the file access?

A security team is implementing a SIEM and needs to ensure that log sources are properly normalized and enriched to support effective correlation and alerting. Which TWO of the following tasks are essential for achieving this goal? (Choose two.)

Question 19hardmultiple choice
Read the full VPN explanation →

A security analyst is reviewing a SIEM alert indicating multiple failed VPN authentication attempts followed by a successful login from an unusual geographic location for the same user account. The analyst wants to determine if this is a compromised account or a legitimate user traveling. Which additional data source would best help the analyst make this determination?

A security analyst is reviewing logs from a Linux web server that has been compromised. The analyst notices a large number of requests to a specific URL that include encoded characters such as %27, %20, and %3D. The web server logs show these requests in the access log with a 200 OK response. Which type of attack is most likely indicated by these log entries?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Log Management and SIEM sessions

Start a Log Management and SIEM only practice session

Every question in these sessions is drawn from the Log Management and SIEM domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Log Management and SIEM?
Read raw logs, decode encoded payloads, verify log-source configuration, and correlate related events across sources. The single most important skill is distinguishing benign noise from a real multi-event attack pattern before escalating.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Log Management and SIEM questions in a focused session?
Yes — the session launcher on this page draws every question from the Log Management and SIEM domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.