Security Event Monitoring Quiz

5 questions Pass: 70% +25 pts

Quiz covering Monitor Security

Security Event Monitoring Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which of the following components is primarily responsible for collecting and aggregating log data from various sources across a network for security analysis?

  2. 2

    An administrator notices a massive spike in failed login attempts followed by a successful login from an unusual geographical location. Which security monitoring concept best describes this activity?

  3. 3

    When configuring log retention policies, what is the most important factor to consider to ensure effective incident response?

  4. 4

    You are monitoring a network and notice an internal workstation attempting to establish outbound connections to a known command-and-control (C2) server over an unusual port. What is the most appropriate first action?

  5. 5

    A security analyst is tuning a SIEM to reduce alert fatigue. They observe that a specific service account triggers an 'Unauthorized Access' alert every time a scheduled backup task runs. Which tuning action is most appropriate?