Choose one response for every question. The test will not submit until all questions are answered. Correct answers and explanations appear only after submission.
Assessment Domains
What This Test Measures
SIEM Foundations
Questions 1–6
Purpose, collection, normalization, correlation, and alert contracts.
Decision Quality
Questions 7–12
Severity, confidence, priority, triage questions, evidence, and alternatives.
Escalation and Cases
Questions 13–17
Escalation, owner deadlines, case notes, actions, validation, and source health.
Dashboards and Quality
Questions 18–23
Metrics, denominators, balanced measures, root cause, grouping, and tuning validation.
Lifecycle and Safety
Questions 24–25
Closure, reopening, ethics, privacy, and complete fictionalization.
Question 1 of 25
SIEM Purpose
Which statement best describes the fictional purpose of a SIEM?
Question 2 of 25
Log Collection
A fictional source is connected, but records arrive twenty minutes late. Which statement is strongest?
Question 3 of 25
Normalization
Why should fictional source values remain traceable after normalization?
Question 4 of 25
Normalization
A fictional extension source is delayed and shows no visible extension. What is the strongest normalized state?
Question 5 of 25
Correlation
Which fictional correlation is most useful for a stale-authority alert?
Question 6 of 25
Alert Rules
What should a strong fictional alert contract include?
Question 7 of 25
Severity and Priority
Which statement correctly separates severity from priority?
Question 8 of 25
Confidence
A fictional role and session source are Healthy, but extension and group sources are limited. Which assessment is strongest?
Question 9 of 25
Priority
Which fictional condition most strongly supports High priority?
Question 10 of 25
Triage Questions
Which fictional triage question is most professional?
Question 11 of 25
Evidence Review
What should a fictional evidence note include?
Question 12 of 25
Alternative Explanations
Why should fictional analysts document alternative explanations?
Question 13 of 25
Escalation
What is fictional escalation?
Question 14 of 25
Escalation
A fictional identity owner misses a deadline while a privileged session remains active. What is the strongest response?
Question 15 of 25
Case Management
Which fictional case note is strongest?
Question 16 of 25
Case Management
Why should fictional actions and outcomes be documented separately?
Question 17 of 25
Source Health
A required fictional source is Blind during the key alert period. Which case state is strongest?
Question 18 of 25
Dashboards
A fictional dashboard shows an average review time of eight minutes, but several High-priority alerts waited more than one hour. What should be added?
Question 19 of 25
Metrics
Why must a fictional rate define its denominator?
Question 20 of 25
Metrics
Which fictional metric set is most balanced?
Question 21 of 25
Noise Reduction
What is the strongest first step when a fictional alert creates too much noise?
Question 22 of 25
Grouping
Which fictional condition should usually break alert grouping?
Question 23 of 25
Tuning Validation
Shadow mode reduces fictional raw alerts by 60% but hides a changed destination. What should happen?
Question 24 of 25
Closure and Reopening
When is a fictional case ready for closure?
Question 25 of 25
Safety and Ethics
Which approach is required for a public CyberShield SIEM portfolio artifact?
Submission Status
25 questions remaining
Answers and explanations stay hidden until you submit.
Safety Boundary
This Assessment Is Entirely Fictional and Defensive
The test does not authorize access, investigation, monitoring, collection, querying, tuning, suppression, escalation, response, or changes involving any real SIEM, alert, case, account, endpoint, network, domain, service, supplier, organization, or person.
Module Navigation
Return to A6
Review your results, revisit the lessons connected to any missed domains, and use the module homepage to confirm that every A6 page is complete.