Question 31

An organization is implementing and deploying the SIEM with following capabilities.

What kind of SIEM deployment architecture the organization is planning to implement?
  • Question 32

    Which of the following directory will contain logs related to printer access?
  • Question 33

    A SOC analyst receives an alert indicating that the system time on a critical Windows server was changed at 3:
    00 AM. There are no scheduled maintenance tasks at this time. Unauthorized time changes can be used to evade security controls, such as altering timestamps to obscure malicious activity. The analyst must identify the relevant event codes that log system time modifications and related suspicious behavior. Which of the following Windows Security Event Codes should the analyst review to investigate potential tampering?
  • Question 34

    Global Solutions Inc. uses syslog for centralized logging across a geographically diverse network. The SOC team must ensure logs are reliably delivered from remote sites to the central logging server across potentially unreliable network connections. To guarantee consistent and dependable log delivery, which syslog architectural layer should they focus on optimizing and hardening?
  • Question 35

    An attacker exploits the logic validation mechanisms of an e-commerce website. He successfully purchases a product worth $100 for $10 by modifying the URL exchanged between the client and the server.
    Original
    URL: http://www.buyonline.com/product.aspx?profile=12
    &debit=100
    Modified URL: http://www.buyonline.com/product.aspx?profile=12
    &debit=10
    Identify the attack depicted in the above scenario.