1. What is Log aggregation ? Junior A. User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity B. an attacker altering or deleting logs to hide their activity, countered by immutable logging C. scalable store for large volumes of raw security telemetry queried for hunting and analytics D. collecting logs from many sources into a central store for search and analysis Reveal the answer + AI explanation — free account
2. Which term means: "collecting logs from many sources into a central store for search and analysis"? Junior A. Alert fatigue B. MITRE ATT&CK C. UEBA D. Log aggregation Reveal the answer + AI explanation — free account
3. Which statement is correct? Junior A. Log aggregation — an attacker altering or deleting logs to hide their activity, countered by immutable logging B. Log aggregation — collecting logs from many sources into a central store for search and analysis C. Log aggregation — designing, testing, and maintaining rules and analytics that surface malicious activity D. Log aggregation — automated notification triggered when monitored data matches a detection rule Reveal the answer + AI explanation — free account
4. What is Audit log ? Junior A. collecting logs from many sources into a central store for search and analysis B. designing, testing, and maintaining rules and analytics that surface malicious activity C. SIEM logic linking events across sources to detect a multi-step attack pattern D. record of security-relevant events such as logins, permission changes, and access Reveal the answer + AI explanation — free account
5. Which term means: "record of security-relevant events such as logins, permission changes, and access"? Junior A. Detection engineering B. Audit log C. Alert D. Correlation rule Reveal the answer + AI explanation — free account
6. Which statement is correct? Junior A. Audit log — User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity B. Audit log — record of security-relevant events such as logins, permission changes, and access C. Audit log — policy defining how long logs are kept to satisfy investigation and compliance needs D. Audit log — designing, testing, and maintaining rules and analytics that surface malicious activity Reveal the answer + AI explanation — free account
7. What is Alert ? Junior A. scalable store for large volumes of raw security telemetry queried for hunting and analytics B. record of security-relevant events such as logins, permission changes, and access C. automated notification triggered when monitored data matches a detection rule D. User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity Reveal the answer + AI explanation — free account
8. Which term means: "automated notification triggered when monitored data matches a detection rule"? Junior A. Alert B. Detection-as-code C. MITRE ATT&CK D. Detection engineering Reveal the answer + AI explanation — free account
9. Which statement is correct? Junior A. Alert — SIEM logic linking events across sources to detect a multi-step attack pattern B. Alert — policy defining how long logs are kept to satisfy investigation and compliance needs C. Alert — knowledge base of adversary tactics and techniques used to map detection coverage D. Alert — automated notification triggered when monitored data matches a detection rule Reveal the answer + AI explanation — free account
10. What is Log retention ? Junior A. policy defining how long logs are kept to satisfy investigation and compliance needs B. collecting logs from many sources into a central store for search and analysis C. record of security-relevant events such as logins, permission changes, and access D. designing, testing, and maintaining rules and analytics that surface malicious activity Reveal the answer + AI explanation — free account
11. Which term means: "policy defining how long logs are kept to satisfy investigation and compliance needs"? Junior A. Detection-as-code B. Detection engineering C. Log retention D. Alert Reveal the answer + AI explanation — free account
12. Which statement is correct? Junior A. Log retention — automated notification triggered when monitored data matches a detection rule B. Log retention — managing detection rules in version control with testing and CI like software C. Log retention — policy defining how long logs are kept to satisfy investigation and compliance needs D. Log retention — an attacker altering or deleting logs to hide their activity, countered by immutable logging Reveal the answer + AI explanation — free account
13. What is Correlation rule ? Mid A. policy defining how long logs are kept to satisfy investigation and compliance needs B. managing detection rules in version control with testing and CI like software C. SIEM logic linking events across sources to detect a multi-step attack pattern D. an attacker altering or deleting logs to hide their activity, countered by immutable logging Reveal the answer + AI explanation — free account
14. Which term means: "SIEM logic linking events across sources to detect a multi-step attack pattern"? Mid A. Audit log B. Alert C. Correlation rule D. UEBA Reveal the answer + AI explanation — free account
15. Which statement is correct? Mid A. Correlation rule — automated notification triggered when monitored data matches a detection rule B. Correlation rule — designing, testing, and maintaining rules and analytics that surface malicious activity C. Correlation rule — SIEM logic linking events across sources to detect a multi-step attack pattern D. Correlation rule — policy defining how long logs are kept to satisfy investigation and compliance needs Reveal the answer + AI explanation — free account
16. What is Detection engineering ? Mid A. desensitization from excessive or noisy alerts that causes real threats to be missed B. scalable store for large volumes of raw security telemetry queried for hunting and analytics C. designing, testing, and maintaining rules and analytics that surface malicious activity D. collecting logs from many sources into a central store for search and analysis Reveal the answer + AI explanation — free account
17. Which term means: "designing, testing, and maintaining rules and analytics that surface malicious activity"? Mid A. Log tampering B. UEBA C. Detection engineering D. Detection-as-code Reveal the answer + AI explanation — free account
18. Which statement is correct? Mid A. Detection engineering — policy defining how long logs are kept to satisfy investigation and compliance needs B. Detection engineering — record of security-relevant events such as logins, permission changes, and access C. Detection engineering — knowledge base of adversary tactics and techniques used to map detection coverage D. Detection engineering — designing, testing, and maintaining rules and analytics that surface malicious activity Reveal the answer + AI explanation — free account
19. What is Alert fatigue ? Mid A. policy defining how long logs are kept to satisfy investigation and compliance needs B. managing detection rules in version control with testing and CI like software C. desensitization from excessive or noisy alerts that causes real threats to be missed D. an attacker altering or deleting logs to hide their activity, countered by immutable logging Reveal the answer + AI explanation — free account
20. Which term means: "desensitization from excessive or noisy alerts that causes real threats to be missed"? Mid A. Alert fatigue B. Log retention C. UEBA D. MITRE ATT&CK Reveal the answer + AI explanation — free account
21. Which statement is correct? Mid A. Alert fatigue — desensitization from excessive or noisy alerts that causes real threats to be missed B. Alert fatigue — policy defining how long logs are kept to satisfy investigation and compliance needs C. Alert fatigue — collecting logs from many sources into a central store for search and analysis D. Alert fatigue — designing, testing, and maintaining rules and analytics that surface malicious activity Reveal the answer + AI explanation — free account
22. What is Log tampering ? Mid A. scalable store for large volumes of raw security telemetry queried for hunting and analytics B. an attacker altering or deleting logs to hide their activity, countered by immutable logging C. managing detection rules in version control with testing and CI like software D. User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity Reveal the answer + AI explanation — free account
23. Which term means: "an attacker altering or deleting logs to hide their activity, countered by immutable logging"? Mid A. UEBA B. Log tampering C. Alert fatigue D. Detection engineering Reveal the answer + AI explanation — free account
24. Which statement is correct? Mid A. Log tampering — record of security-relevant events such as logins, permission changes, and access B. Log tampering — managing detection rules in version control with testing and CI like software C. Log tampering — collecting logs from many sources into a central store for search and analysis D. Log tampering — an attacker altering or deleting logs to hide their activity, countered by immutable logging Reveal the answer + AI explanation — free account
25. What is UEBA ? Senior A. designing, testing, and maintaining rules and analytics that surface malicious activity B. User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity C. automated notification triggered when monitored data matches a detection rule D. scalable store for large volumes of raw security telemetry queried for hunting and analytics Reveal the answer + AI explanation — free account
26. Which term means: "User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity"? Senior A. Alert B. UEBA C. Detection engineering D. Detection-as-code Reveal the answer + AI explanation — free account
27. Which statement is correct? Senior A. UEBA — User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity B. UEBA — automated notification triggered when monitored data matches a detection rule C. UEBA — desensitization from excessive or noisy alerts that causes real threats to be missed D. UEBA — collecting logs from many sources into a central store for search and analysis Reveal the answer + AI explanation — free account
28. What is MITRE ATT&CK ? Senior A. an attacker altering or deleting logs to hide their activity, countered by immutable logging B. knowledge base of adversary tactics and techniques used to map detection coverage C. scalable store for large volumes of raw security telemetry queried for hunting and analytics D. record of security-relevant events such as logins, permission changes, and access Reveal the answer + AI explanation — free account
29. Which term means: "knowledge base of adversary tactics and techniques used to map detection coverage"? Senior A. MITRE ATT&CK B. Detection-as-code C. Data lake (security) D. Correlation rule Reveal the answer + AI explanation — free account
30. Which statement is correct? Senior A. MITRE ATT&CK — User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity B. MITRE ATT&CK — desensitization from excessive or noisy alerts that causes real threats to be missed C. MITRE ATT&CK — knowledge base of adversary tactics and techniques used to map detection coverage D. MITRE ATT&CK — record of security-relevant events such as logins, permission changes, and access Reveal the answer + AI explanation — free accountShowing 30 of 36 Logging & SIEM questions — the full set, with answers, explanations and an AI tutor on every question, is inside.