Unit 1: SOC Fundamentals and Incident Response - Practice Quiz

INT244 — Securing Computing Systems 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What is the primary purpose of a Security Operations Center (SOC)?

Introduction to SOC: overview of SOC Easy
A. To repair office equipment
B. To monitor and protect an organization's systems
C. To manage employee salaries
D. To design company websites

2 Why is a SOC important to an organization?

Introduction to SOC: importance of SOC Easy
A. It helps detect and respond to security threats
B. It prevents employees from using email
C. It reduces the need for computer networks
D. It replaces all software developers

3 Which is a common challenge faced by a SOC?

Introduction to SOC: challenges in SOC Easy
A. Too many printed documents
B. Too much computer storage
C. Too few office chairs
D. Too many security alerts

4 What is a typical responsibility of a SOC analyst?

Introduction to SOC: roles and responsibilities Easy
A. Managing building access cards
B. Reviewing security alerts
C. Creating advertising campaigns
D. Preparing employee meals

5 Which SOC model is operated by an organization's own security team?

Introduction to SOC: models Easy
A. Personal SOC
B. Public SOC
C. Temporary SOC
D. Internal SOC

6 What do SOC pillars generally represent?

SOC Pillars: introduction Easy
A. Core areas of SOC operations
B. Types of office furniture
C. Methods of network cabling
D. Categories of programming languages

7 Which activity belongs to the detection pillar of a SOC?

SOC Pillars: definition of SOC pillars Easy
A. Identifying suspicious activity
B. Designing company logos
C. Writing employee contracts
D. Ordering computer equipment

8 Why are SOC pillars important?

SOC Pillars: importance of SOC pillars Easy
A. They organize security activities
B. They replace security policies
C. They eliminate all security risks
D. They remove the need for monitoring

9 Which SOC analyst level usually handles basic alert monitoring and triage?

SOC Pillars: levels of SOC analysis Easy
A. Level 1 analyst
B. Level 2 analyst
C. Level 3 analyst
D. Level 4 analyst

10 What should a SOC team consider when prioritizing security alerts?

SOC Pillars: prioritization and analysis Easy
A. The alert's font color
B. The number of office computers
C. The analyst's favorite tool
D. Potential impact and severity

11 What is the goal of remediation after a security incident?

SOC Pillars: remediation and recovery Easy
A. Remove the threat and fix affected systems
B. Disable every user account
C. Delete all security logs
D. Ignore the affected systems

12 What is the purpose of a security assessment or audit?

SOC Pillars: assessment and audit Easy
A. To evaluate security controls
B. To replace operating systems monthly
C. To create social media content
D. To increase internet speed

13 What does threat intelligence provide to a SOC?

SOC Pillars: threat intelligence Easy
A. A list of employee holidays
B. Information about current threats
C. Instructions for office cleaning
D. Computer hardware discounts

14 Which phase of the incident response lifecycle involves identifying a possible incident?

Security Incident Response: incident response lifecycle Easy
A. Detection
B. Recovery
C. Lessons learned
D. Preparation

15 What is the main purpose of the preparation phase in incident response?

Security Incident Response: incident response lifecycle Easy
A. Plan and prepare response capabilities
B. Replace all network devices
C. Delete evidence from systems
D. Publish the incident publicly

16 Why should investigators preserve security logs during an incident?

Security Incident Response: handling and investigation technique Easy
A. They may provide useful evidence
B. They automatically stop the attack
C. They increase network bandwidth
D. They remove malware immediately

17 What is a key purpose of post-incident analysis?

Security Incident Response: post-incident analysis Easy
A. Identify improvements for future incidents
B. Stop collecting security data
C. Remove all response procedures
D. Hide the incident from all staff

18 What is an important rule when sharing incident information?

Security Incident Response: information sharing in incident response Easy
A. Share it with authorized parties
B. Send it to unknown recipients
C. Remove all identifying information automatically
D. Post all details on public websites

19 Which communication practice is best during a security incident?

Security Incident Response: communication strategies Easy
A. Send unrelated information
B. Provide clear and timely updates
C. Delay every important message
D. Use confusing technical language

20 What should an organization do first when a confirmed incident affects an important server?

Security Incident Response: incident response in IT environment Easy
A. Ignore the incident temporarily
B. Turn off every device immediately
C. Erase the server's logs
D. Follow the incident response plan

21 A company notices that security alerts are being handled inconsistently by different IT teams. Which SOC capability would most directly address this problem?

Introduction to SOC: overview of SOC Medium
A. Annual replacement of network hardware
B. Removal of all remote-access services
C. Centralized monitoring and coordinated response
D. Migration of every application to cloud hosting

22 Why does continuous SOC monitoring generally reduce the impact of security incidents?

Introduction to SOC: importance of SOC Medium
A. It identifies suspicious activity before damage expands
B. It guarantees that attackers cannot access systems
C. It eliminates the need for user security training
D. It prevents every vulnerability from being created

23 A SOC receives thousands of alerts daily, but only a small number represent real attacks. Which challenge is illustrated?

Introduction to SOC: challenges in SOC Medium
A. Insufficient physical security at the office
B. Alert fatigue caused by excessive false positives
C. Excessive segmentation of internal networks
D. Lack of encryption in archived documents

24 During an active ransomware incident, which responsibility best fits a SOC analyst?

Introduction to SOC: roles and responsibilities Medium
A. Design the company's public advertising campaign
B. Rewrite all employee employment contracts
C. Review alerts and validate suspicious activity
D. Approve the organization's annual budget

25 An organization operates its own monitoring team, infrastructure, and incident response process. Which SOC model is being used?

Introduction to SOC: models Medium
A. An internally managed SOC
B. A temporary incident-only SOC
C. A vendor-neutral audit SOC
D. A fully outsourced SOC

26 A SOC improves detection but repeatedly fails to contain incidents and restore services. Which conclusion is most appropriate?

SOC Pillars: introduction Medium
A. The organization should disable all automated alerts
B. Incident response is unrelated to SOC effectiveness
C. Its security functions are not balanced across the SOC pillars
D. Detection alone is sufficient for complete protection

27 Which statement best describes SOC pillars?

SOC Pillars: definition of SOC pillars Medium
A. They are separate passwords used by SOC analysts
B. They are physical zones inside a security operations center
C. They are related capability areas supporting security operations
D. They are legal penalties assigned after every breach

28 Why are SOC pillars useful when an organization evaluates its security operations?

SOC Pillars: importance of SOC pillars Medium
A. They ensure all security incidents have identical causes
B. They restrict analysts to reviewing only network traffic
C. They replace the need to define security objectives
D. They reveal capability gaps across the security process

29 An analyst correlates firewall, endpoint, and identity logs to determine whether several alerts are part of one attack. Which analysis level is most clearly involved?

SOC Pillars: levels of SOC analysis Medium
A. Basic device inventory collection
B. Advanced correlation and incident analysis
C. Routine password expiration management
D. Physical access badge administration

30 Which alert should a SOC prioritize first?

SOC Pillars: prioritization and analysis Medium
A. A routine antivirus update on a workstation
B. A confirmed compromise of a critical database server
C. A user entering an incorrect password once
D. A blocked scan from an unknown external address

31 After confirming that an endpoint is infected, which action best supports remediation and recovery?

SOC Pillars: remediation and recovery Medium
A. Delete all logs before rebuilding the endpoint
B. Reconnect the endpoint immediately to test the network
C. Ignore the infection after changing the user's password
D. Isolate the endpoint, remove the malware, and restore safely

32 An audit finds that analysts do not consistently document containment decisions. What is the main value of this finding?

SOC Pillars: assessment and audit Medium
A. It proves that no security incident has occurred
B. It identifies a process weakness requiring corrective action
C. It confirms that technical controls are unnecessary
D. It shows that all analysts should use identical passwords

33 A threat intelligence report identifies the command-and-control domain used by a known attacker group. How should the SOC use this information?

SOC Pillars: threat intelligence Medium
A. Publish the domain publicly before validating the report
B. Remove all domain name resolution from the organization
C. Create detections and search historical activity for the domain
D. Assume every connection to the internet is malicious

34 Which sequence best represents a typical incident response lifecycle?

Security Incident Response: incident response lifecycle Medium
A. Preparation, detection, containment, eradication, recovery, lessons learned
B. Containment, publicity, detection, recovery, preparation, deletion
C. Detection, recovery, preparation, containment, publicity, eradication
D. Recovery, preparation, eradication, detection, containment, audit

35 An analyst suspects that a workstation is communicating with an attacker. Which investigation step is most appropriate initially?

Security Incident Response: handling and investigation technique Medium
A. Reformat the workstation before collecting any evidence
B. Preserve relevant evidence and examine network connections
C. Announce the suspected attacker identity to all employees
D. Disconnect every system in the organization immediately

36 A post-incident review shows that an alert was generated but remained unassigned for six hours. What improvement is most relevant?

Security Incident Response: post-incident analysis Medium
A. Remove the alert rule to reduce analyst workload
B. Require users to investigate alerts without SOC support
C. Stop recording timestamps during future incidents
D. Define alert ownership and escalation time targets

37 Why should incident responders share validated indicators with relevant internal teams?

Security Incident Response: information sharing in incident response Medium
A. Other teams can search for related activity and strengthen defenses
B. Internal teams can replace all forensic analysis with the indicators
C. Indicators eliminate the need to preserve incident evidence
D. Sharing indicators guarantees that the incident is fully resolved

38 During a major incident, which communication practice is most effective?

Security Incident Response: communication strategies Medium
A. Share every preliminary suspicion with the public
B. Delay all communication until the incident is completely understood
C. Provide approved, timely updates tailored to each audience
D. Use technical logs as the only update for executives

39 A compromised virtual server hosts a business-critical application. Which response action best balances containment and availability?

Security Incident Response: incident response in IT environment Medium
A. Delete the virtual server immediately without preserving evidence
B. Isolate the affected instance and fail over to a verified clean system
C. Shut down every production server without checking dependencies
D. Leave the server online until the business day ends

40 A SOC manager is deciding how to improve coverage outside normal business hours. Which responsibility is most relevant to this decision?

Introduction to SOC: roles and responsibilities Medium
A. Designing staffing, escalation, and operational coverage
B. Approving individual employee vacation destinations
C. Selecting colors for the organization's security dashboard
D. Replacing all incident tickets with informal conversations

41 A SOC receives an alert that an administrator account authenticated from an unusual country. Which action best reflects the SOC's core function?

Introduction to SOC: overview of SOC Hard
A. Reset all administrator passwords immediately
B. Close the alert because geolocation is unreliable
C. Correlate identity, endpoint, network, and behavioral evidence
D. Block every connection from that country

42 An organization has deployed strong preventive controls but still experiences occasional credential compromise. Which SOC capability most directly reduces the resulting business impact?

Introduction to SOC: importance of SOC Hard
A. Mandatory encryption of every internal message
B. Continuous detection and coordinated containment
C. Annual replacement of perimeter firewalls
D. Removal of all externally accessible services

43 A SOC has a high alert volume, but analysts spend most of their time investigating benign events and miss a real ransomware intrusion. Which underlying challenge is most evident?

Introduction to SOC: challenges in SOC Hard
A. Overreliance on physical access controls
B. Insufficient cryptographic key rotation
C. Excessive false positives and alert fatigue
D. Inadequate software licensing records

44 During an active breach, which division of responsibility is most appropriate?

Introduction to SOC: roles and responsibilities Hard
A. The analyst approves legal notifications and public statements
B. The SOC manager performs every forensic acquisition
C. The incident commander coordinates actions and decision authority
D. The threat hunter restores systems without change approval

45 An organization operates a small internal monitoring team but contracts a provider for overnight monitoring and specialized investigations. Which SOC model best describes this arrangement?

Introduction to SOC: models Hard
A. Hybrid SOC
B. Distributed SOC without external support
C. Fully internal SOC
D. Fully outsourced SOC

46 A SOC redesign groups its program into people, process, technology, intelligence, and measurement. What is the principal benefit of this pillar-based view?

SOC Pillars: introduction Hard
A. It exposes capability gaps across interdependent functions
B. It replaces the need for incident-specific judgment
C. It guarantees that incidents will be prevented
D. It limits security operations to technical controls

47 Which statement best defines SOC pillars in an operational context?

SOC Pillars: definition of SOC pillars Hard
A. A hierarchy of incident severity classifications
B. Independent products purchased from security vendors
C. Foundational capability areas supporting detection and response
D. A checklist used only during compliance examinations

48 A SOC owns an advanced SIEM but has inconsistent escalation procedures and no validated contact roster. Which conclusion follows from the pillar model?

SOC Pillars: importance of SOC pillars Hard
A. Technology eliminates the process deficiency
B. The SIEM should be replaced before processes are reviewed
C. The contact roster is unrelated to SOC maturity
D. The SOC has a capability imbalance despite strong tooling

49 An alert has been correlated with a known malicious domain, but the analyst must determine whether the activity represents a coordinated intrusion. Which analysis level is most appropriate next?

SOC Pillars: levels of SOC analysis Hard
A. Triage-level alert acknowledgment
B. Asset-level inventory reconciliation
C. Event-level log formatting
D. Incident-level scope and campaign analysis

50 Two alerts have equal confidence. Alert A affects a public web server with limited privileges; Alert B affects a domain administrator workstation showing lateral movement. Which should receive higher priority?

SOC Pillars: prioritization and analysis Hard
A. Alert B because privilege and propagation risk are greater
B. Both alerts because confidence determines priority alone
C. Alert A because web traffic is easier to investigate
D. Alert A because public systems are always urgent

51 After containing malware on several endpoints, which recovery decision is most defensible before returning systems to production?

SOC Pillars: remediation and recovery Hard
A. Delete the detection rule after the malware is removed
B. Rebuild or restore from trusted sources and verify controls
C. Reconnect isolated hosts to test whether symptoms recur
D. Restore from the newest backup without validation

52 An audit finds that incident tickets are consistently closed within the target time, but no evidence shows whether containment was effective. What weakness does this reveal?

SOC Pillars: assessment and audit Hard
A. The SOC measures speed without validating outcome quality
B. Containment effectiveness cannot be assessed operationally
C. The audit should examine only ticket closure timestamps
D. The SOC has no need for measurable response objectives

53 A threat feed reports an IP address associated with a botnet, but the address is also used by a cloud hosting provider. What should the SOC do before blocking it globally?

SOC Pillars: threat intelligence Hard
A. Ignore it because infrastructure indicators are never useful
B. Block it immediately because every feed indicator is definitive
C. Validate context, scope, recency, and observed malicious behavior
D. Replace the feed with a list of internal IP addresses

54 Which sequence most accurately represents a conventional incident response lifecycle?

Security Incident Response: incident response lifecycle Hard
A. Recovery, preparation, containment, lessons learned
B. Preparation, detection and analysis, containment, eradication and recovery, lessons learned
C. Containment, preparation, recovery, detection, audit
D. Detection, public disclosure, eradication, preparation, recovery

55 An endpoint suspected of compromise is still powered on and may contain volatile evidence. Which action best balances investigation and containment?

Security Incident Response: handling and investigation technique Hard
A. Immediately power it off and discard volatile evidence
B. Reboot it repeatedly to test whether the alert persists
C. Allow unrestricted network access until imaging is complete
D. Capture relevant volatile data, then isolate the endpoint

56 A post-incident review determines that a compromised account had excessive privileges, but the report blames only the analyst who missed the alert. What is the main deficiency?

Security Incident Response: post-incident analysis Hard
A. The analyst should be assigned all remediation tasks
B. The review should exclude identity-control weaknesses
C. The report should contain only technical indicators
D. The review focuses on individual blame instead of systemic causes

57 Before sharing an incident indicator with an industry information-sharing group, which consideration is most important?

Security Incident Response: information sharing in incident response Hard
A. Whether sharing removes the need to preserve evidence
B. Whether every internal log can be included without filtering
C. Whether the indicator has a visually distinctive format
D. Whether the indicator can be shared with context and authorization

58 During a major outage caused by a suspected cyberattack, which communication practice is most appropriate?

Security Incident Response: communication strategies Hard
A. Delay all communication until the investigation is complete
B. Provide regular factual updates with owners and next actions
C. Allow every technical team to issue independent statements
D. Release unverified attribution to demonstrate transparency

59 A response team isolates a production database server without consulting application owners, causing a critical service outage. Which improvement best addresses the failure?

Security Incident Response: incident response in IT environment Hard
A. Permit analysts to make all service-impacting decisions
B. Use risk-based playbooks with business-owner escalation paths
C. Wait for executive approval before every containment action
D. Prohibit containment of production systems

60 Investigators find that a malicious PowerShell process spawned from a document viewer, accessed a token, and then initiated remote service execution. Which technique best supports scoping the intrusion?

Security Incident Response: handling and investigation technique Hard
A. Construct a process, identity, and lateral-movement timeline
B. Search only for the original malware hash
C. Delete all PowerShell logs to prevent duplication
D. Review only the originating document's filename