Correct Answer: Identify improvements for future incidents
Explanation:
Post-incident analysis reviews the response and identifies lessons that can improve future security operations.
Incorrect! Try again.
18What is an important rule when sharing incident information?
Security Incident Response: information sharing in incident response
Easy
A.Share it with authorized parties
B.Send it to unknown recipients
C.Remove all identifying information automatically
D.Post all details on public websites
Correct Answer: Share it with authorized parties
Explanation:
Incident information should be shared carefully with people and organizations that are authorized and need to know.
Incorrect! Try again.
19Which communication practice is best during a security incident?
Security Incident Response: communication strategies
Easy
A.Send unrelated information
B.Provide clear and timely updates
C.Delay every important message
D.Use confusing technical language
Correct Answer: Provide clear and timely updates
Explanation:
Clear and timely communication helps stakeholders understand the incident and coordinate an effective response.
Incorrect! Try again.
20What should an organization do first when a confirmed incident affects an important server?
Security Incident Response: incident response in IT environment
Easy
A.Ignore the incident temporarily
B.Turn off every device immediately
C.Erase the server's logs
D.Follow the incident response plan
Correct Answer: Follow the incident response plan
Explanation:
Following the approved response plan helps the organization contain the incident while preserving evidence and coordinating actions.
Incorrect! Try again.
21A company notices that security alerts are being handled inconsistently by different IT teams. Which SOC capability would most directly address this problem?
Introduction to SOC: overview of SOC
Medium
A.Annual replacement of network hardware
B.Removal of all remote-access services
C.Centralized monitoring and coordinated response
D.Migration of every application to cloud hosting
Correct Answer: Centralized monitoring and coordinated response
Explanation:
A SOC centralizes security monitoring, analysis, and response procedures so incidents are handled consistently.
Incorrect! Try again.
22Why does continuous SOC monitoring generally reduce the impact of security incidents?
Introduction to SOC: importance of SOC
Medium
A.It identifies suspicious activity before damage expands
B.It guarantees that attackers cannot access systems
C.It eliminates the need for user security training
D.It prevents every vulnerability from being created
Correct Answer: It identifies suspicious activity before damage expands
Explanation:
Continuous monitoring can shorten the time between compromise and detection, allowing containment actions to begin earlier.
Incorrect! Try again.
23A SOC receives thousands of alerts daily, but only a small number represent real attacks. Which challenge is illustrated?
Introduction to SOC: challenges in SOC
Medium
A.Insufficient physical security at the office
B.Alert fatigue caused by excessive false positives
C.Excessive segmentation of internal networks
D.Lack of encryption in archived documents
Correct Answer: Alert fatigue caused by excessive false positives
Explanation:
A high volume of non-actionable alerts can overwhelm analysts and make important events harder to identify.
Incorrect! Try again.
24During an active ransomware incident, which responsibility best fits a SOC analyst?
Introduction to SOC: roles and responsibilities
Medium
A.Design the company's public advertising campaign
B.Rewrite all employee employment contracts
C.Review alerts and validate suspicious activity
D.Approve the organization's annual budget
Correct Answer: Review alerts and validate suspicious activity
Explanation:
SOC analysts examine alerts, correlate evidence, and determine whether activity indicates a security incident.
Incorrect! Try again.
25An organization operates its own monitoring team, infrastructure, and incident response process. Which SOC model is being used?
Introduction to SOC: models
Medium
A.An internally managed SOC
B.A temporary incident-only SOC
C.A vendor-neutral audit SOC
D.A fully outsourced SOC
Correct Answer: An internally managed SOC
Explanation:
An internally managed SOC is staffed and operated by the organization using its own security resources.
Incorrect! Try again.
26A SOC improves detection but repeatedly fails to contain incidents and restore services. Which conclusion is most appropriate?
SOC Pillars: introduction
Medium
A.The organization should disable all automated alerts
B.Incident response is unrelated to SOC effectiveness
C.Its security functions are not balanced across the SOC pillars
D.Detection alone is sufficient for complete protection
Correct Answer: Its security functions are not balanced across the SOC pillars
A.They are separate passwords used by SOC analysts
B.They are physical zones inside a security operations center
C.They are related capability areas supporting security operations
D.They are legal penalties assigned after every breach
Correct Answer: They are related capability areas supporting security operations
Explanation:
SOC pillars organize the major functions needed to monitor, analyze, respond to, and improve security operations.
Incorrect! Try again.
28Why are SOC pillars useful when an organization evaluates its security operations?
SOC Pillars: importance of SOC pillars
Medium
A.They ensure all security incidents have identical causes
B.They restrict analysts to reviewing only network traffic
C.They replace the need to define security objectives
D.They reveal capability gaps across the security process
Correct Answer: They reveal capability gaps across the security process
Explanation:
Using pillars helps an organization assess whether important operational capabilities are missing or underdeveloped.
Incorrect! Try again.
29An analyst correlates firewall, endpoint, and identity logs to determine whether several alerts are part of one attack. Which analysis level is most clearly involved?
SOC Pillars: levels of SOC analysis
Medium
A.Basic device inventory collection
B.Advanced correlation and incident analysis
C.Routine password expiration management
D.Physical access badge administration
Correct Answer: Advanced correlation and incident analysis
Explanation:
Correlating multiple data sources to identify an attack pattern requires analysis beyond reviewing isolated alerts.
Incorrect! Try again.
30Which alert should a SOC prioritize first?
SOC Pillars: prioritization and analysis
Medium
A.A routine antivirus update on a workstation
B.A confirmed compromise of a critical database server
C.A user entering an incorrect password once
D.A blocked scan from an unknown external address
Correct Answer: A confirmed compromise of a critical database server
Explanation:
Priority should reflect both confidence that an incident exists and the potential business impact of the affected asset.
Incorrect! Try again.
31After confirming that an endpoint is infected, which action best supports remediation and recovery?
SOC Pillars: remediation and recovery
Medium
A.Delete all logs before rebuilding the endpoint
B.Reconnect the endpoint immediately to test the network
C.Ignore the infection after changing the user's password
D.Isolate the endpoint, remove the malware, and restore safely
Correct Answer: Isolate the endpoint, remove the malware, and restore safely
Explanation:
Isolation limits spread, remediation removes the threat, and controlled restoration returns the system to operation.
Incorrect! Try again.
32An audit finds that analysts do not consistently document containment decisions. What is the main value of this finding?
SOC Pillars: assessment and audit
Medium
A.It proves that no security incident has occurred
B.It identifies a process weakness requiring corrective action
C.It confirms that technical controls are unnecessary
D.It shows that all analysts should use identical passwords
Correct Answer: It identifies a process weakness requiring corrective action
Explanation:
Assessment and audit activities identify weaknesses in controls, procedures, evidence, and compliance so they can be improved.
Incorrect! Try again.
33A threat intelligence report identifies the command-and-control domain used by a known attacker group. How should the SOC use this information?
SOC Pillars: threat intelligence
Medium
A.Publish the domain publicly before validating the report
B.Remove all domain name resolution from the organization
C.Create detections and search historical activity for the domain
D.Assume every connection to the internet is malicious
Correct Answer: Create detections and search historical activity for the domain
Explanation:
Threat intelligence becomes operationally useful when indicators guide detection, hunting, and investigation activities.
Incorrect! Try again.
34Which sequence best represents a typical incident response lifecycle?
Security Incident Response: incident response lifecycle
Medium
C.Selecting colors for the organization's security dashboard
D.Replacing all incident tickets with informal conversations
Correct Answer: Designing staffing, escalation, and operational coverage
Explanation:
SOC management includes planning staffing models, escalation paths, and coverage needed to support continuous operations.
Incorrect! Try again.
41A SOC receives an alert that an administrator account authenticated from an unusual country. Which action best reflects the SOC's core function?
Introduction to SOC: overview of SOC
Hard
A.Reset all administrator passwords immediately
B.Close the alert because geolocation is unreliable
C.Correlate identity, endpoint, network, and behavioral evidence
D.Block every connection from that country
Correct Answer: Correlate identity, endpoint, network, and behavioral evidence
Explanation:
A SOC converts disparate telemetry into contextualized findings before selecting a proportionate response.
Incorrect! Try again.
42An organization has deployed strong preventive controls but still experiences occasional credential compromise. Which SOC capability most directly reduces the resulting business impact?
Introduction to SOC: importance of SOC
Hard
A.Mandatory encryption of every internal message
B.Continuous detection and coordinated containment
C.Annual replacement of perimeter firewalls
D.Removal of all externally accessible services
Correct Answer: Continuous detection and coordinated containment
Explanation:
A SOC limits dwell time and blast radius by detecting suspicious activity and coordinating containment after preventive controls fail.
Incorrect! Try again.
43A SOC has a high alert volume, but analysts spend most of their time investigating benign events and miss a real ransomware intrusion. Which underlying challenge is most evident?
Introduction to SOC: challenges in SOC
Hard
A.Overreliance on physical access controls
B.Insufficient cryptographic key rotation
C.Excessive false positives and alert fatigue
D.Inadequate software licensing records
Correct Answer: Excessive false positives and alert fatigue
Explanation:
Poor detection precision consumes analyst capacity, increasing the probability that high-impact alerts are delayed or overlooked.
Incorrect! Try again.
44During an active breach, which division of responsibility is most appropriate?
Introduction to SOC: roles and responsibilities
Hard
A.The analyst approves legal notifications and public statements
B.The SOC manager performs every forensic acquisition
C.The incident commander coordinates actions and decision authority
D.The threat hunter restores systems without change approval
Correct Answer: The incident commander coordinates actions and decision authority
Explanation:
An incident commander maintains operational coordination and assigns decisions, while analysts, forensic specialists, legal staff, and communications teams retain their specialties.
Incorrect! Try again.
45An organization operates a small internal monitoring team but contracts a provider for overnight monitoring and specialized investigations. Which SOC model best describes this arrangement?
Introduction to SOC: models
Hard
A.Hybrid SOC
B.Distributed SOC without external support
C.Fully internal SOC
D.Fully outsourced SOC
Correct Answer: Hybrid SOC
Explanation:
A hybrid SOC combines internally retained capabilities with externally provided monitoring or specialist services.
Incorrect! Try again.
46A SOC redesign groups its program into people, process, technology, intelligence, and measurement. What is the principal benefit of this pillar-based view?
SOC Pillars: introduction
Hard
A.It exposes capability gaps across interdependent functions
B.It replaces the need for incident-specific judgment
C.It guarantees that incidents will be prevented
D.It limits security operations to technical controls
Correct Answer: It exposes capability gaps across interdependent functions
Explanation:
Pillars provide a structured way to assess whether operational capability is balanced rather than concentrated in one area.
Incorrect! Try again.
47Which statement best defines SOC pillars in an operational context?
SOC Pillars: definition of SOC pillars
Hard
A.A hierarchy of incident severity classifications
B.Independent products purchased from security vendors
C.Foundational capability areas supporting detection and response
D.A checklist used only during compliance examinations
Correct Answer: Foundational capability areas supporting detection and response
Explanation:
SOC pillars describe the foundational domains that collectively enable reliable security monitoring, analysis, response, and improvement.
Incorrect! Try again.
48A SOC owns an advanced SIEM but has inconsistent escalation procedures and no validated contact roster. Which conclusion follows from the pillar model?
SOC Pillars: importance of SOC pillars
Hard
A.Technology eliminates the process deficiency
B.The SIEM should be replaced before processes are reviewed
C.The contact roster is unrelated to SOC maturity
D.The SOC has a capability imbalance despite strong tooling
Correct Answer: The SOC has a capability imbalance despite strong tooling
Explanation:
Effective SOC performance depends on coordinated people, processes, and technology; a powerful platform cannot compensate for response gaps.
Incorrect! Try again.
49An alert has been correlated with a known malicious domain, but the analyst must determine whether the activity represents a coordinated intrusion. Which analysis level is most appropriate next?
SOC Pillars: levels of SOC analysis
Hard
A.Triage-level alert acknowledgment
B.Asset-level inventory reconciliation
C.Event-level log formatting
D.Incident-level scope and campaign analysis
Correct Answer: Incident-level scope and campaign analysis
Explanation:
Once an indicator is credible, incident-level analysis examines related events, affected assets, attacker objectives, and the broader intrusion pattern.
Incorrect! Try again.
50Two alerts have equal confidence. Alert A affects a public web server with limited privileges; Alert B affects a domain administrator workstation showing lateral movement. Which should receive higher priority?
SOC Pillars: prioritization and analysis
Hard
A.Alert B because privilege and propagation risk are greater
B.Both alerts because confidence determines priority alone
C.Alert A because web traffic is easier to investigate
D.Alert A because public systems are always urgent
Correct Answer: Alert B because privilege and propagation risk are greater
Explanation:
Prioritization should combine confidence with asset criticality, privilege level, attack progression, and potential business impact.
Incorrect! Try again.
51After containing malware on several endpoints, which recovery decision is most defensible before returning systems to production?
SOC Pillars: remediation and recovery
Hard
A.Delete the detection rule after the malware is removed
B.Rebuild or restore from trusted sources and verify controls
C.Reconnect isolated hosts to test whether symptoms recur
D.Restore from the newest backup without validation
Correct Answer: Rebuild or restore from trusted sources and verify controls
Explanation:
Recovery requires trusted restoration, validation of system integrity, confirmation that persistence is removed, and monitoring for recurrence.
Incorrect! Try again.
52An audit finds that incident tickets are consistently closed within the target time, but no evidence shows whether containment was effective. What weakness does this reveal?
SOC Pillars: assessment and audit
Hard
A.The SOC measures speed without validating outcome quality
B.Containment effectiveness cannot be assessed operationally
C.The audit should examine only ticket closure timestamps
D.The SOC has no need for measurable response objectives
Correct Answer: The SOC measures speed without validating outcome quality
Explanation:
A mature assessment evaluates both efficiency metrics and effectiveness evidence, such as eradication success, recurrence, and residual exposure.
Incorrect! Try again.
53A threat feed reports an IP address associated with a botnet, but the address is also used by a cloud hosting provider. What should the SOC do before blocking it globally?
SOC Pillars: threat intelligence
Hard
A.Ignore it because infrastructure indicators are never useful
B.Block it immediately because every feed indicator is definitive
C.Validate context, scope, recency, and observed malicious behavior
D.Replace the feed with a list of internal IP addresses
Correct Answer: Validate context, scope, recency, and observed malicious behavior
Explanation:
Threat intelligence requires contextual validation because shared infrastructure and stale indicators can produce harmful false positives.
Incorrect! Try again.
54Which sequence most accurately represents a conventional incident response lifecycle?
Security Incident Response: incident response lifecycle
Hard
D.Detection, public disclosure, eradication, preparation, recovery
Correct Answer: Preparation, detection and analysis, containment, eradication and recovery, lessons learned
Explanation:
The lifecycle begins with preparation, proceeds through analysis and response, restores operations, and concludes with improvement based on lessons learned.
Incorrect! Try again.
55An endpoint suspected of compromise is still powered on and may contain volatile evidence. Which action best balances investigation and containment?
Security Incident Response: handling and investigation technique
Hard
A.Immediately power it off and discard volatile evidence
B.Reboot it repeatedly to test whether the alert persists
C.Allow unrestricted network access until imaging is complete
D.Capture relevant volatile data, then isolate the endpoint
Correct Answer: Capture relevant volatile data, then isolate the endpoint
Explanation:
Volatile evidence can disappear after shutdown, while isolation limits additional attacker activity; the sequence should follow approved forensic procedures.
Incorrect! Try again.
56A post-incident review determines that a compromised account had excessive privileges, but the report blames only the analyst who missed the alert. What is the main deficiency?
Security Incident Response: post-incident analysis
Hard
A.The analyst should be assigned all remediation tasks
B.The review should exclude identity-control weaknesses
C.The report should contain only technical indicators
D.The review focuses on individual blame instead of systemic causes
Correct Answer: The review focuses on individual blame instead of systemic causes
Explanation:
Effective reviews identify control, process, training, and design failures so that corrective actions reduce recurrence rather than merely assign blame.
Incorrect! Try again.
57Before sharing an incident indicator with an industry information-sharing group, which consideration is most important?
Security Incident Response: information sharing in incident response
Hard
A.Whether sharing removes the need to preserve evidence
B.Whether every internal log can be included without filtering
C.Whether the indicator has a visually distinctive format
D.Whether the indicator can be shared with context and authorization
Correct Answer: Whether the indicator can be shared with context and authorization
Explanation:
Useful sharing requires appropriate authorization, privacy and legal review, handling restrictions, and enough context to support defensive action.
Incorrect! Try again.
58During a major outage caused by a suspected cyberattack, which communication practice is most appropriate?
Security Incident Response: communication strategies
Hard
A.Delay all communication until the investigation is complete
B.Provide regular factual updates with owners and next actions
C.Allow every technical team to issue independent statements
D.Release unverified attribution to demonstrate transparency
Correct Answer: Provide regular factual updates with owners and next actions
Explanation:
Crisis communication should be coordinated, factual, audience-appropriate, and clear about current impact, actions, uncertainty, and next updates.
Incorrect! Try again.
59A response team isolates a production database server without consulting application owners, causing a critical service outage. Which improvement best addresses the failure?
Security Incident Response: incident response in IT environment
Hard
A.Permit analysts to make all service-impacting decisions
B.Use risk-based playbooks with business-owner escalation paths
C.Wait for executive approval before every containment action
D.Prohibit containment of production systems
Correct Answer: Use risk-based playbooks with business-owner escalation paths
Explanation:
IT response must balance security urgency with operational impact through predefined decision criteria, technical safeguards, and appropriate owner involvement.
Incorrect! Try again.
60Investigators find that a malicious PowerShell process spawned from a document viewer, accessed a token, and then initiated remote service execution. Which technique best supports scoping the intrusion?
Security Incident Response: handling and investigation technique
Hard
A.Construct a process, identity, and lateral-movement timeline
B.Search only for the original malware hash
C.Delete all PowerShell logs to prevent duplication
D.Review only the originating document's filename
Correct Answer: Construct a process, identity, and lateral-movement timeline
Explanation:
A correlated timeline links execution chains, credential access, identities, and movement across hosts, revealing scope beyond a single file hash.
Incorrect! Try again.
Did this save you a night before the exam?
LPU Notes is free, and it stays free. Ads cover part of the server bill.
The rest comes out of a student's own pocket: the domain, the storage,
and keeping the site up through the weeks everyone needs it at once.
The payment button didn't load. An ad blocker or a filtered network is the usual reason.
to try again.
Nothing here is ever locked, and nothing unlocks. Chip in only if it was worth it.
What it pays for →