36 Logging & SIEM questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.
Free to start: the 2-minute IT readiness check — six questions and a result.
A.User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity
B.an attacker altering or deleting logs to hide their activity, countered by immutable logging
C.scalable store for large volumes of raw security telemetry queried for hunting and analytics
D.collecting logs from many sources into a central store for search and analysis
Answer + AI explanation with Pro
2. Which term means: "collecting logs from many sources into a central store for search and analysis"?
Junior
A.Alert fatigue
B.MITRE ATT&CK
C.UEBA
D.Log aggregation
Answer + AI explanation with Pro
3. Which statement is correct?
Junior
A.Log aggregation — an attacker altering or deleting logs to hide their activity, countered by immutable logging
B.Log aggregation — collecting logs from many sources into a central store for search and analysis
C.Log aggregation — designing, testing, and maintaining rules and analytics that surface malicious activity
D.Log aggregation — automated notification triggered when monitored data matches a detection rule
Answer + AI explanation with Pro
4. What is Audit log?
Junior
A.collecting logs from many sources into a central store for search and analysis
B.designing, testing, and maintaining rules and analytics that surface malicious activity
C.SIEM logic linking events across sources to detect a multi-step attack pattern
D.record of security-relevant events such as logins, permission changes, and access
Answer + AI explanation with Pro
5. Which term means: "record of security-relevant events such as logins, permission changes, and access"?
Junior
A.Detection engineering
B.Audit log
C.Alert
D.Correlation rule
Answer + AI explanation with Pro
6. Which statement is correct?
Junior
A.Audit log — User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity
B.Audit log — record of security-relevant events such as logins, permission changes, and access
C.Audit log — policy defining how long logs are kept to satisfy investigation and compliance needs
D.Audit log — designing, testing, and maintaining rules and analytics that surface malicious activity
Answer + AI explanation with Pro
7. What is Alert?
Junior
A.scalable store for large volumes of raw security telemetry queried for hunting and analytics
B.record of security-relevant events such as logins, permission changes, and access
C.automated notification triggered when monitored data matches a detection rule
D.User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity
Answer + AI explanation with Pro
8. Which term means: "automated notification triggered when monitored data matches a detection rule"?
Junior
A.Alert
B.Detection-as-code
C.MITRE ATT&CK
D.Detection engineering
Answer + AI explanation with Pro
9. Which statement is correct?
Junior
A.Alert — SIEM logic linking events across sources to detect a multi-step attack pattern
B.Alert — policy defining how long logs are kept to satisfy investigation and compliance needs
C.Alert — knowledge base of adversary tactics and techniques used to map detection coverage
D.Alert — automated notification triggered when monitored data matches a detection rule
Answer + AI explanation with Pro
10. What is Log retention?
Junior
A.policy defining how long logs are kept to satisfy investigation and compliance needs
B.collecting logs from many sources into a central store for search and analysis
C.record of security-relevant events such as logins, permission changes, and access
D.designing, testing, and maintaining rules and analytics that surface malicious activity
Answer + AI explanation with Pro
11. Which term means: "policy defining how long logs are kept to satisfy investigation and compliance needs"?
Junior
A.Detection-as-code
B.Detection engineering
C.Log retention
D.Alert
Answer + AI explanation with Pro
12. Which statement is correct?
Junior
A.Log retention — automated notification triggered when monitored data matches a detection rule
B.Log retention — managing detection rules in version control with testing and CI like software
C.Log retention — policy defining how long logs are kept to satisfy investigation and compliance needs
D.Log retention — an attacker altering or deleting logs to hide their activity, countered by immutable logging
Answer + AI explanation with Pro
13. What is Correlation rule?
Mid
A.policy defining how long logs are kept to satisfy investigation and compliance needs
B.managing detection rules in version control with testing and CI like software
C.SIEM logic linking events across sources to detect a multi-step attack pattern
D.an attacker altering or deleting logs to hide their activity, countered by immutable logging
Answer + AI explanation with Pro
14. Which term means: "SIEM logic linking events across sources to detect a multi-step attack pattern"?
Mid
A.Audit log
B.Alert
C.Correlation rule
D.UEBA
Answer + AI explanation with Pro
15. Which statement is correct?
Mid
A.Correlation rule — automated notification triggered when monitored data matches a detection rule
B.Correlation rule — designing, testing, and maintaining rules and analytics that surface malicious activity
C.Correlation rule — SIEM logic linking events across sources to detect a multi-step attack pattern
D.Correlation rule — policy defining how long logs are kept to satisfy investigation and compliance needs
Answer + AI explanation with Pro
16. What is Detection engineering?
Mid
A.desensitization from excessive or noisy alerts that causes real threats to be missed
B.scalable store for large volumes of raw security telemetry queried for hunting and analytics
C.designing, testing, and maintaining rules and analytics that surface malicious activity
D.collecting logs from many sources into a central store for search and analysis
Answer + AI explanation with Pro
17. Which term means: "designing, testing, and maintaining rules and analytics that surface malicious activity"?
Mid
A.Log tampering
B.UEBA
C.Detection engineering
D.Detection-as-code
Answer + AI explanation with Pro
18. Which statement is correct?
Mid
A.Detection engineering — policy defining how long logs are kept to satisfy investigation and compliance needs
B.Detection engineering — record of security-relevant events such as logins, permission changes, and access
C.Detection engineering — knowledge base of adversary tactics and techniques used to map detection coverage
D.Detection engineering — designing, testing, and maintaining rules and analytics that surface malicious activity
Answer + AI explanation with Pro
19. What is Alert fatigue?
Mid
A.policy defining how long logs are kept to satisfy investigation and compliance needs
B.managing detection rules in version control with testing and CI like software
C.desensitization from excessive or noisy alerts that causes real threats to be missed
D.an attacker altering or deleting logs to hide their activity, countered by immutable logging
Answer + AI explanation with Pro
20. Which term means: "desensitization from excessive or noisy alerts that causes real threats to be missed"?
Mid
A.Alert fatigue
B.Log retention
C.UEBA
D.MITRE ATT&CK
Answer + AI explanation with Pro
21. Which statement is correct?
Mid
A.Alert fatigue — desensitization from excessive or noisy alerts that causes real threats to be missed
B.Alert fatigue — policy defining how long logs are kept to satisfy investigation and compliance needs
C.Alert fatigue — collecting logs from many sources into a central store for search and analysis
D.Alert fatigue — designing, testing, and maintaining rules and analytics that surface malicious activity
Answer + AI explanation with Pro
22. What is Log tampering?
Mid
A.scalable store for large volumes of raw security telemetry queried for hunting and analytics
B.an attacker altering or deleting logs to hide their activity, countered by immutable logging
C.managing detection rules in version control with testing and CI like software
D.User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity
Answer + AI explanation with Pro
23. Which term means: "an attacker altering or deleting logs to hide their activity, countered by immutable logging"?
Mid
A.UEBA
B.Log tampering
C.Alert fatigue
D.Detection engineering
Answer + AI explanation with Pro
24. Which statement is correct?
Mid
A.Log tampering — record of security-relevant events such as logins, permission changes, and access
B.Log tampering — managing detection rules in version control with testing and CI like software
C.Log tampering — collecting logs from many sources into a central store for search and analysis
D.Log tampering — an attacker altering or deleting logs to hide their activity, countered by immutable logging
Answer + AI explanation with Pro
25. What is UEBA?
Senior
A.designing, testing, and maintaining rules and analytics that surface malicious activity
B.User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity
C.automated notification triggered when monitored data matches a detection rule
D.scalable store for large volumes of raw security telemetry queried for hunting and analytics
Answer + AI explanation with Pro
26. Which term means: "User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity"?
Senior
A.Alert
B.UEBA
C.Detection engineering
D.Detection-as-code
Answer + AI explanation with Pro
27. Which statement is correct?
Senior
A.UEBA — User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity
B.UEBA — automated notification triggered when monitored data matches a detection rule
C.UEBA — desensitization from excessive or noisy alerts that causes real threats to be missed
D.UEBA — collecting logs from many sources into a central store for search and analysis
Answer + AI explanation with Pro
28. What is MITRE ATT&CK?
Senior
A.an attacker altering or deleting logs to hide their activity, countered by immutable logging
B.knowledge base of adversary tactics and techniques used to map detection coverage
C.scalable store for large volumes of raw security telemetry queried for hunting and analytics
D.record of security-relevant events such as logins, permission changes, and access
Answer + AI explanation with Pro
29. Which term means: "knowledge base of adversary tactics and techniques used to map detection coverage"?
Senior
A.MITRE ATT&CK
B.Detection-as-code
C.Data lake (security)
D.Correlation rule
Answer + AI explanation with Pro
30. Which statement is correct?
Senior
A.MITRE ATT&CK — User and Entity Behavior Analytics baselining normal behavior to flag anomalous activity
B.MITRE ATT&CK — desensitization from excessive or noisy alerts that causes real threats to be missed
C.MITRE ATT&CK — knowledge base of adversary tactics and techniques used to map detection coverage
D.MITRE ATT&CK — record of security-relevant events such as logins, permission changes, and access
Answer + AI explanation with Pro
Showing 30 of 36 Logging & SIEM questions — the full set, with answers, explanations and an AI tutor on every question, is inside.
Free to start
Start with a free readiness check
Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Logging & SIEM question come with Pro.