Security Analyst Investigating a SIEM Correlation Alert Quiz

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 8865 | Total Attempts: 106,055
| Questions: 20 | Updated: Aug 13, 2026
Please wait...
Question 1 / 21
🏆 Rank #--
0 %
0/100
Score 0/100

1. When investigating a SIEM alert, what is the primary purpose of threat intelligence enrichment?

Submit
Please wait...
About This Quiz
Security Analyst Investigating A Siem Correlation Alert Quiz - Quiz

This quiz evaluates your ability to investigate SIEM correlation alerts as a security analyst. You will assess log analysis, threat detection, incident response procedures, and forensic techniques essential to the CompTIA CySA+ certification. Master the skills needed to identify, analyze, and respond to security events in enterprise environments.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. When documenting a SIEM investigation for compliance, which element is most critical to include?

Submit

3. A SIEM correlation alert combines three separate security events within a 5-minute window. What is this detection method called?

Submit

4. In incident response, which step immediately follows SIEM alert triage and validation?

Submit

5. A SIEM alert shows a service account performing interactive logins, which is abnormal. This is an example of what type of anomaly detection?

Submit

6. When a SIEM correlation alert triggers, what does 'baselining' refer to in the investigation context?

Submit

7. An analyst reviews a SIEM alert for privilege escalation. Which Windows event ID is most relevant?

Submit

8. During forensic investigation of a SIEM alert, what is the correct order of volatile data preservation?

Submit

9. True or False: SIEM correlation rules should be tuned to alert on every possible security event to maximize detection.

Submit

10. A SIEM alert indicates unusual outbound traffic on port 443 from a workstation. Which log source would best confirm this is HTTPS traffic versus tunneling?

Submit

11. A SIEM correlation alert triggers when a user account fails authentication 15 times in 2 minutes from different source IPs. What attack pattern does this indicate?

Submit

12. An analyst discovers that a SIEM alert for data exfiltration was triggered by a scheduled backup job. How should this be handled?

Submit

13. Which metric is most important when tuning SIEM correlation rules to reduce false positives?

Submit

14. A SIEM correlation rule combines data from firewall, proxy, and endpoint logs. This approach is called?

Submit

15. During incident investigation, an analyst needs to preserve evidence chain of custody. Which action is NOT appropriate?

Submit

16. What does the term 'false positive' mean in SIEM correlation rules?

Submit

17. A SIEM alert shows multiple failed login attempts followed by a successful login using a service account. What investigation technique should you apply first?

Submit

18. Which log source provides the most reliable evidence of lateral movement within a network?

Submit

19. An analyst receives a SIEM alert showing a user accessing sensitive files at 3 AM on a weekend. What is the first step in investigation?

Submit

20. Which SIEM component is responsible for normalizing log data from multiple sources into a standardized format?

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (20)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
When investigating a SIEM alert, what is the primary purpose of threat...
When documenting a SIEM investigation for compliance, which element is...
A SIEM correlation alert combines three separate security events...
In incident response, which step immediately follows SIEM alert triage...
A SIEM alert shows a service account performing interactive logins,...
When a SIEM correlation alert triggers, what does 'baselining' refer...
An analyst reviews a SIEM alert for privilege escalation. Which...
During forensic investigation of a SIEM alert, what is the correct...
True or False: SIEM correlation rules should be tuned to alert on...
A SIEM alert indicates unusual outbound traffic on port 443 from a...
A SIEM correlation alert triggers when a user account fails...
An analyst discovers that a SIEM alert for data exfiltration was...
Which metric is most important when tuning SIEM correlation rules to...
A SIEM correlation rule combines data from firewall, proxy, and...
During incident investigation, an analyst needs to preserve evidence...
What does the term 'false positive' mean in SIEM correlation rules?
A SIEM alert shows multiple failed login attempts followed by a...
Which log source provides the most reliable evidence of lateral...
An analyst receives a SIEM alert showing a user accessing sensitive...
Which SIEM component is responsible for normalizing log data from...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!