Search Tags
Browse questions by tags on Wikique.
Questions Tagged "SIEM"
Found 10 results for "SIEM"
1. An administrator performs a potentially risky configuration change during an approved maintenance window with a valid change ticket. How should this context affect the investigation?
2. A user downloads a large number of sensitive files, creates an archive, and then uploads it to an external cloud service. Which combination provides the strongest investigation context?
3. A user grants a newly registered third-party application permission to read their mailbox. Why should this event be investigated?
4. An unknown scheduled task creates a PowerShell process every hour on a server. What is the most likely security concern?
5. Which endpoint event provides the most useful context for determining how a suspicious process was executed?
6. Which event should generally receive the highest priority during a SOC investigation?
7. A Conditional Access policy blocks authentication from an unmanaged device. Which event would be most useful to determine whether the policy worked as intended?
8. An attacker has obtained a user's password but repeatedly fails MFA. Which additional event would be most important for investigation?
9. Which sign-in event is the strongest indicator of a possible credential-compromise attempt?
10. Which of the following is the abbreviation of MTBF?
About This Tag
Showing questions related to the tag "SIEM".
Explore Wikique
Explore practice questions across different categories and subjects.
Browse CategoriesBrowse Categories
General Knowledge
4 Questions
Competitive Exams
5 Questions
History & Geography
99 Questions
Entrance Exams
4 Questions
Technology & Computers
316 Questions
Aptitude & Reasoning
4 Questions
Languages & Literature
43 Questions
Professional & Career
37 Questions
Lifestyle, Culture & Trivia
4 Questions
Sports & Entertainment
43 Questions
Business, Finance & Economics
4 Questions
Current Affairs
26 Questions