Unit 4: Response Automation and SOC Metrics - Practice Quiz

INT244 — Securing Computing Systems 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What is the main purpose of incident response automation?

Incident Response Automation and Orchestration: introduction Easy
A. To prevent every possible attack
B. To speed up routine response tasks
C. To remove all security staff
D. To replace all network devices

2 Which result commonly shows that automation has improved a SOC?

Incident Response Automation and Orchestration: evaluating the impact of automation in SOCs Easy
A. Faster alert handling
B. More manual data entry
C. Fewer documented procedures
D. Longer investigation times

3 What is the role of a playbook in incident response?

Incident Response Automation and Orchestration: role of playbooks Easy
A. It replaces security policies
B. It stores employee salaries
C. It provides response steps
D. It designs network hardware

4 What is a threat-specific playbook designed to address?

Incident Response Automation and Orchestration: threat-specific versus generic playbooks Easy
A. A particular type of threat
B. General office activities
C. Only hardware failures
D. Every business process

5 In automated incident response, what does gathering usually involve?

Incident Response Automation and Orchestration: gathering and application Easy
A. Deleting all historical alerts
B. Changing user job titles
C. Purchasing new office furniture
D. Collecting relevant incident information

6 Why should a SOC collect information from diverse sources?

Incident Response Automation and Orchestration: collection from diverse sources Easy
A. To make alerts less accurate
B. To gain a broader view of incidents
C. To reduce the number of data points
D. To avoid using security tools

7 Which measure is commonly used to assess response efficiency?

Incident Response Automation and Orchestration: measuring efficiency and effectiveness Easy
A. Number of office floors
B. Mean time to respond
C. Length of employee names
D. Size of the parking area

8 How can automation improve SOC performance?

Incident Response Automation and Orchestration: improving SOC performance Easy
A. By delaying analyst decisions
B. By hiding all security alerts
C. By removing incident records
D. By handling repetitive tasks

9 How can SOC metrics support cyber resilience?

SOC Metrics and Performance Measurement: advancing cyber resilience with insights Easy
A. They guarantee that attacks never occur
B. They eliminate the need for backups
C. They replace all security controls
D. They reveal areas for improvement

10 What does performance measurement help a SOC understand?

SOC Metrics and Performance Measurement: performance measurement Easy
A. Which employees take vacations
B. Where unrelated products are sold
C. How much office space is available
D. How well its processes work

11 What is the purpose of anomaly detection in a SOC?

SOC Metrics and Performance Measurement: anomaly detection Easy
A. To create employee accounts
B. To format business documents
C. To identify unusual activity
D. To schedule routine meetings

12 Which metric measures the average time between detecting and resolving an incident?

SOC Metrics and Performance Measurement: metrics for evaluating incident response Easy
A. Mean time to resolve
B. Daily network bandwidth
C. Total number of analysts
D. Annual software license count

13 What does a skills investment gap assessment identify?

SOC Metrics and Performance Measurement: skills investment gap assessment Easy
A. Unused office equipment
B. Changes in building access
C. Differences in software colors
D. Missing skills and training needs

14 Which financial metric can help evaluate the cost of SOC operations?

SOC Metrics and Performance Measurement: financial metrics for evaluating Easy
A. Cost per incident
B. Average password length
C. Number of threat categories
D. Count of network protocols

15 How can AI and machine learning assist SOC operations?

SOC Metrics and Performance Measurement: AI/ML Easy
A. By removing all human judgment
B. By turning off security monitoring
C. By detecting patterns in data
D. By preventing the need for updates

16 Which is a likely future trend in SOC metrics?

SOC Metrics and Performance Measurement: future trends in SOC metrics Easy
A. Removal of all performance reports
B. Less attention to response times
C. Fewer useful security records
D. More predictive measurements

17 Which is a core area commonly measured in a SOC?

SOC Metrics and Performance Measurement: core areas for SOC metrics Easy
A. Employee clothing style
B. Incident response time
C. Office decoration quality
D. cafeteria menu variety

18 What is one possible risk of poorly designed automation?

Incident Response Automation and Orchestration: evaluating the impact of automation in SOCs Easy
A. Faster routine analysis
B. Incorrect actions on alerts
C. Reduced repetitive work
D. Improved response consistency

19 What is a generic playbook intended to provide?

Incident Response Automation and Orchestration: threat-specific versus generic playbooks Easy
A. A list of employee benefits
B. A replacement for threat intelligence
C. A broadly applicable response process
D. A response for one malware family

20 Which metric can help measure the quality of alert handling?

SOC Metrics and Performance Measurement: core areas for SOC metrics Easy
A. Amount of screen brightness
B. Number of office chairs
C. False positive rate
D. Length of security uniforms

21 A SOC wants to reduce repetitive manual actions during incident handling. Which capability best represents incident response automation and orchestration?

Incident Response Automation and Orchestration: introduction Medium
A. Increasing the number of security reports created each month
B. Storing every alert without applying response actions
C. Automatically executing coordinated response actions across security tools
D. Replacing all analysts with a single monitoring platform

22 After automating phishing triage, which result provides the strongest evidence that the automation improved SOC performance?

Incident Response Automation and Orchestration: evaluating the impact of automation in SOCs Medium
A. The SOC purchases additional security monitoring software
B. Analysts spend less time per case while accuracy remains stable
C. More alerts are displayed on the analyst dashboard
D. The playbook contains more steps than the previous process

23 What is the primary purpose of a playbook in an automated incident response process?

Incident Response Automation and Orchestration: role of playbooks Medium
A. To provide unrestricted access to every security system
B. To record only the final severity of each incident
C. To define repeatable steps, decision points, and response actions
D. To replace the organization’s cybersecurity policies

24 A SOC is responding to ransomware incidents that require file-hash checks, endpoint isolation, and recovery coordination. Why would a threat-specific playbook be preferable to a generic one?

Incident Response Automation and Orchestration: threat-specific versus generic playbooks Medium
A. It applies actions tailored to the threat’s indicators and behavior
B. It prevents analysts from modifying response decisions
C. It removes the need for incident documentation
D. It guarantees that every alert is classified as critical

25 During an investigation, an orchestration platform gathers threat intelligence about a suspicious domain and automatically enriches the related alert. What is the main benefit?

Incident Response Automation and Orchestration: gathering and application Medium
A. It eliminates the need to preserve evidence
B. It guarantees that the domain is malicious
C. It provides context that supports faster and better-informed decisions
D. It converts all alerts into confirmed incidents

26 Why should an automated response workflow collect data from endpoints, identity systems, firewalls, and threat intelligence feeds?

Incident Response Automation and Orchestration: collection from diverse sources Medium
A. To create a broader view of the incident and improve correlation
B. To ensure that only network alerts are investigated
C. To make every source produce identical event records
D. To avoid using timestamps during incident analysis

27 Which combination best measures both the efficiency and effectiveness of an automated response workflow?

Incident Response Automation and Orchestration: measuring efficiency and effectiveness Medium
A. Number of dashboards and number of security policies
B. Amount of log storage and length of incident reports
C. Number of analysts and number of office locations
D. Mean response time and percentage of correctly contained incidents

28 A playbook frequently isolates legitimate business systems because its trigger conditions are too broad. What is the most appropriate improvement?

Incident Response Automation and Orchestration: improving SOC performance Medium
A. Refine conditions and add approval or exception checks
B. Disable all automated containment actions
C. Remove event enrichment from the playbook
D. Increase the number of alerts sent to analysts

29 How can SOC metrics contribute to cyber resilience rather than merely report historical activity?

SOC Metrics and Performance Measurement: advancing cyber resilience with insights Medium
A. By identifying weaknesses and guiding improvements before similar incidents recur
B. By measuring only the total number of alerts received
C. By replacing risk assessments with analyst opinions
D. By prioritizing the tools with the most dashboard widgets

30 A SOC reports that it closed 95% of tickets within its target time, but major incidents continued to cause long outages. What does this suggest about the measurement approach?

SOC Metrics and Performance Measurement: performance measurement Medium
A. The number of closed tickets proves that resilience improved
B. The target time should be removed from all incident categories
C. The SOC needs more metrics related to incident impact and outcomes
D. Ticket closure time is always sufficient for performance evaluation

31 A baseline shows that a user normally accesses systems during business hours from one country. An automated metric flags repeated nighttime access from several countries. What is the metric primarily detecting?

SOC Metrics and Performance Measurement: anomaly detection Medium
A. A failure of the organization’s backup process
B. A reduction in the number of authentication events
C. A deviation from the user’s established behavioral baseline
D. A confirmed data breach requiring immediate disclosure

32 Which metric most directly measures the time between an incident being detected and the beginning of containment?

SOC Metrics and Performance Measurement: metrics for evaluating incident response Medium
A. Mean time to detect
B. Mean time to contain
C. False-positive notification rate
D. Mean time between failures

33 A skills assessment shows that analysts are strong in alert triage but weak in cloud forensics. Which action best addresses the identified investment gap?

SOC Metrics and Performance Measurement: skills investment gap assessment Medium
A. Evaluate analysts only by the number of tickets they close
B. Increase the alert threshold for every cloud-related detection
C. Stop collecting cloud logs until analysts gain more experience
D. Provide targeted training and measure improvement in cloud investigations

34 Which financial measure is most useful for comparing the value of a response automation project with its cost?

SOC Metrics and Performance Measurement: financial metrics for evaluating Medium
A. Return on investment based on avoided losses and implementation costs
B. Number of pages in the automation documentation
C. Total number of alerts generated after deployment
D. Average age of the SOC’s hardware assets

35 An AI model reduces alert volume by grouping similar events, but analysts discover that some real attacks are being grouped incorrectly. Which metric should be reviewed most urgently?

SOC Metrics and Performance Measurement: AI/ML Medium
A. Number of visualizations on the SOC dashboard
B. Detection recall for confirmed malicious activity
C. Average length of the model’s source code
D. Total number of analyst logins per month

36 Which future trend would make SOC metrics more useful for business decision-making?

SOC Metrics and Performance Measurement: future trends in SOC metrics Medium
A. Linking technical response measures to business risk and service availability
B. Using one universal target for every incident type
C. Reporting only raw event counts without organizational context
D. Removing human review from all metric calculations

37 Which set includes core areas commonly used to evaluate SOC performance?

SOC Metrics and Performance Measurement: core areas for SOC metrics Medium
A. Office size, employee age, travel distance, and meeting count
B. Password length, monitor size, printer speed, and storage color
C. Detection, response, prevention, and continuous improvement
D. Procurement volume, desk capacity, lunch timing, and room usage

38 A SOC automates low-risk account lockouts but requires analyst approval before disabling privileged accounts. What principle does this design demonstrate?

Incident Response Automation and Orchestration: evaluating the impact of automation in SOCs Medium
A. Avoiding automation for all identity incidents
B. Treating privileged accounts as lower-risk assets
C. Applying identical actions to every alert
D. Using different automation levels according to risk

39 An incident response team detects threats quickly, but containment is delayed because incidents are repeatedly reassigned between teams. Which metric would best expose this weakness?

SOC Metrics and Performance Measurement: metrics for evaluating incident response Medium
A. Total volume of archived security logs
B. Number of threat intelligence subscriptions
C. Percentage of endpoints with antivirus software
D. Mean time to contain

40 An automated playbook receives timestamps from systems configured in different time zones. What should the SOC do before correlating events?

Incident Response Automation and Orchestration: collection from diverse sources Medium
A. Discard events from systems outside headquarters
B. Normalize timestamps to a common time reference
C. Treat every timestamp as the analyst’s local time
D. Sort events by the size of their log files

41 A SOC wants to automate containment of endpoint alerts. Which design principle most directly reduces the risk that automation amplifies a false positive into a business outage?

Incident Response Automation and Orchestration: introduction Hard
A. Let analysts approve every automated enrichment step
B. Automate only alerts with the highest severity
C. Require deterministic evidence and bounded rollback actions
D. Prioritize alerts using the oldest timestamp first

42 After automation is introduced, mean time to respond decreases by 40%, but the rate of reopened incidents doubles. Which conclusion is most defensible?

Incident Response Automation and Orchestration: evaluating the impact of automation in SOCs Hard
A. Automation improved response effectiveness without qualification
B. Analysts are probably generating too many low-priority alerts
C. Response speed improved, but containment quality may have degraded
D. Reopened incidents should be excluded from performance reporting

43 A playbook contains conditional branches, approval gates, evidence requirements, and rollback actions. What is its primary operational value?

Incident Response Automation and Orchestration: role of playbooks Hard
A. It guarantees that every incident has the same severity
B. It converts all detection rules into automated responses
C. It replaces the need for analyst judgment
D. It standardizes repeatable decisions while preserving controlled escalation

44 When is a threat-specific playbook preferable to a generic malware-response playbook?

Incident Response Automation and Orchestration: threat-specific versus generic playbooks Hard
A. When every endpoint uses a different security agent
B. When the threat has distinctive evidence and containment requirements
C. When the alert source cannot provide contextual evidence
D. When the SOC has fewer than three analysts

45 A playbook automatically gathers identity, endpoint, DNS, and cloud evidence before recommending containment. Which capability is being demonstrated?

Incident Response Automation and Orchestration: gathering and application Hard
A. Unsupervised incident closure
B. Severity-only prioritization
C. Evidence-driven orchestration
D. Static alert suppression

46 A correlation workflow joins logs from an identity provider, EDR, firewall, and SaaS platform. Which issue is most likely to produce a misleading incident timeline?

Incident Response Automation and Orchestration: collection from diverse sources Hard
A. Different retention periods
B. A high number of enrichment fields
C. Excessive use of severity labels
D. Inconsistent timestamps and identity normalization

47 Which measurement set best distinguishes faster processing from genuinely better incident outcomes?

Incident Response Automation and Orchestration: measuring efficiency and effectiveness Hard
A. CPU usage, storage growth, and log ingestion rate
B. Alert volume, analyst count, and ticket age
C. Playbook count, API calls, and dashboard views
D. MTTD, MTTR, false-positive rate, and recurrence rate

48 A SOC automates enrichment but leaves analysts responsible for manually copying results between tools. Which improvement is most likely to produce the greatest performance gain?

Incident Response Automation and Orchestration: improving SOC performance Hard
A. Add more enrichment sources without changing workflows
B. Integrate case management with automated evidence transfer
C. Increase the number of mandatory approval steps
D. Raise alert severity whenever enrichment is incomplete

49 A quarterly report shows fewer incidents, but critical business services experience longer outages during the incidents that remain. Which metric interpretation is most appropriate?

SOC Metrics and Performance Measurement: advancing cyber resilience with insights Hard
A. Incident frequency alone is insufficient to assess cyber resilience
B. Fewer incidents prove that preventive controls are fully effective
C. The outage measure should be ignored because it is not a SOC metric
D. The SOC is more resilient because incident count decreased

50 A team compares analyst MTTR across two quarters, but the second quarter contains many more complex cloud incidents. What is the strongest measurement correction?

SOC Metrics and Performance Measurement: performance measurement Hard
A. Remove all cloud incidents from both quarters
B. Replace MTTR with total ticket volume
C. Segment results by incident complexity and service impact
D. Compare raw averages without adjustment

51 A metric normally varies seasonally, but a detection system flags every predictable end-of-quarter increase as anomalous. What change would most improve its validity?

SOC Metrics and Performance Measurement: anomaly detection Hard
A. Use a baseline that models seasonality and expected variance
B. Replace the metric with a binary incident count
C. Ignore all deviations during reporting periods
D. Lower the alert threshold for all periods

52 Which metric most directly tests whether containment actions prevent an attacker from regaining access?

SOC Metrics and Performance Measurement: metrics for evaluating incident response Hard
A. Number of analysts assigned
B. Initial triage duration
C. Post-containment recurrence rate
D. Mean time to acknowledge

53 A SOC has strong endpoint expertise but repeatedly delays incidents involving identity federation and cloud control planes. Which assessment provides the most actionable investment decision?

SOC Metrics and Performance Measurement: skills investment gap assessment Hard
A. Compare total training hours across all analysts
B. Measure only the number of security certifications
C. Purchase a second endpoint detection platform
D. Map incident capability requirements against demonstrated skills

54 Which financial measure best evaluates whether an automation project creates value when it reduces analyst effort but requires substantial licensing costs?

SOC Metrics and Performance Measurement: financial metrics for evaluating Hard
A. Total number of automated playbook steps
B. Gross alert volume reduction
C. Net benefit after implementation and operating costs
D. Annual security budget percentage

55 An ML model improves alert prioritization overall but performs poorly on rare incidents affecting critical systems. Which evaluation approach is most appropriate?

SOC Metrics and Performance Measurement: AI/ML Hard
A. Remove rare incidents from the validation dataset
B. Evaluate precision, recall, and critical-asset performance separately
C. Use accuracy as the only success measure
D. Optimize only for the largest alert category

56 Which future-oriented metric would best reflect the effectiveness of a SOC operating in a highly automated environment?

SOC Metrics and Performance Measurement: future trends in SOC metrics Hard
A. Percentage of alerts processed by automation
B. Total volume of telemetry collected
C. Time to restore trusted operations after disruption
D. Number of dashboards maintained

57 Which combination covers the core dimensions needed to evaluate a SOC comprehensively?

SOC Metrics and Performance Measurement: core areas for SOC metrics Hard
A. Compliance status, procurement time, training attendance, and uptime
B. Detection quality, response performance, resilience, and resource efficiency
C. Speed, volume, staffing, and storage
D. Tool count, dashboard count, ticket count, and alert count

58 Automation closes low-confidence alerts after checking only one data source. Which governance control most directly addresses the resulting risk?

Incident Response Automation and Orchestration: evaluating the impact of automation in SOCs Hard
A. Require confidence thresholds and independent corroboration
B. Use the same closure rule for every alert category
C. Hide closed alerts from analyst performance reports
D. Increase the maximum number of closed alerts per hour

59 A generic credential-compromise playbook disables an account immediately, but a threat-specific playbook first checks whether the account is used by a production service. Why is the latter safer?

Incident Response Automation and Orchestration: threat-specific versus generic playbooks Hard
A. It eliminates the need for identity telemetry
B. It prevents all future credential compromises
C. It guarantees that the account was maliciously used
D. It incorporates operational dependencies before containment

60 A sudden drop in detected incidents occurs after a log collector silently loses 30% of endpoint telemetry. Which metric design would help reveal the problem earliest?

SOC Metrics and Performance Measurement: anomaly detection Hard
A. Track only the number of confirmed incidents
B. Track telemetry completeness and source availability
C. Increase the threshold for endpoint detections
D. Use analyst satisfaction as the primary signal