Unit 1: SOC Fundamentals and Incident Response - Subjective Questions

INT244 — Securing Computing Systems • Practice Questions with Detailed Answers

20 questions

1

Define a Security Operations Center (SOC) and explain its primary objectives in an organization.

2

Explain the importance of a SOC in protecting modern IT environments.

3

Discuss the major challenges faced by a SOC and suggest suitable measures to address them.

4

Describe the roles and responsibilities of personnel commonly found in a SOC.

5

Compare the in-house, outsourced, co-managed, and virtual SOC models.

6

What are the SOC pillars? Explain how people, processes, and technology work together in SOC operations.

7

Explain the importance of maintaining balanced and mature SOC pillars.

8

Describe the different levels of SOC analysis and explain how an alert moves through them.

9

Explain how a SOC should prioritize security alerts and incidents for analysis.

10

Describe the remediation and recovery functions of a SOC after a security incident.

11

Explain the role of assessment and audit in measuring and improving SOC effectiveness.

12

Define threat intelligence and describe how it supports SOC detection, prioritization, and response.

13

Describe the complete security incident response lifecycle.

14

Explain the main handling and investigation techniques used during a security incident.

15

Distinguish between containment, eradication, and recovery in incident response, giving an example of each.

16

What is post-incident analysis? Describe the activities and outputs of a lessons-learned review.

17

Discuss the benefits, risks, and principles of information sharing during incident response.

18

Describe effective communication strategies for managing a major security incident.

19

Explain how incident response should be adapted for a hybrid IT environment containing on-premises systems, cloud services, and remote endpoints.

20

A SOC detects repeated failed logins followed by a successful privileged login, unusual data access, and outbound traffic to a known malicious address. Describe how the SOC should prioritize, investigate, respond to, and review this incident.