Be able to read a scenario and classify it: incident type, correct IR role, right BCP/DR metric, or best remediation priority. The single most important thing is matching the question's ask (detect, respond, recover, or prioritize) to the correct concept, not the most technical answer.
Start practicing
Security Operations — choose a session length
Free · No account required
Domain overview
Security Operations covers day-to-day monitoring, detection, response, and recovery: logging and SIEM correlation, incident response phases and team roles, digital forensics and evidence handling, BCP/DR metrics like RTO/RPO, and vulnerability and patch management. Questions are scenario-based, asking you to classify incidents, pick the right role, metric, or prioritization criterion.
Exam objectives
SIEM correlation rules and log sources for detecting brute-force, credential stuffing, and impossible-travel events
Incident response team roles: incident commander, communications lead, and liaison to media and regulators
BCP/DR metrics: RTO, RPO, MTD, and MTBF applied to recovery planning and backup design
Vulnerability management prioritization using CVSS scores, asset criticality, and exploit availability
Confusing RTO with RPO: RTO is acceptable downtime, RPO is acceptable data loss measured in time.
Choosing technical containment steps when the question asks who communicates with media or regulators.
Treating every failed-login burst as a breach instead of recognizing it as a precursor or brute-force attempt.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization's disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours for its critical financial application. Which disaster recovery site would be MOST appropriate to meet this RTO?
2A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should the investigator capture FIRST?
3Which of the following BEST describes the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
4A SOC team is using a SIEM to correlate events from multiple sources. They want to automate responses to common threats. Which technology should they integrate to achieve security orchestration and automation?
5During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?
6Which of the following metrics is used to determine the maximum amount of data loss an organization can tolerate in a disaster?
7An organization is implementing a change management process. Which group is responsible for reviewing and approving major changes?
8What is the PRIMARY purpose of a chain of custody in digital forensics?
9A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?
10A security analyst is examining a memory dump from a compromised workstation. Which TWO tools are commonly used for memory forensics?
11An organization is updating its incident response plan. According to best practices, which THREE components should be included in the plan?
12A company is designing a disaster recovery strategy for its e-commerce platform. The platform requires an RTO of 2 hours and an RPO of 15 minutes. Which TWO strategies would BEST meet these requirements?
13An organization is developing an incident response plan. Which component is responsible for defining the specific conditions that constitute an incident?
14A company is selecting a disaster recovery site for critical applications that must be restored within 4 hours with minimal data loss. Which site type best meets these requirements?
15A SOC analyst receives an alert from the SIEM indicating a large volume of outbound data from a sensitive database server to an external IP address. The analyst queries the SIEM and finds the server communicated with the external IP during non-business hours. Which type of incident is most likely occurring?
16Which metric defines the maximum amount of data loss an organization can tolerate during a disaster?
17A security team is implementing data loss prevention (DLP) to protect sensitive information. Which DLP type is best suited to monitor and block sensitive data leaving the corporate network via email or web traffic?
18Which role in an incident response team is primarily responsible for coordinating communication with external parties, such as the media and regulators?
19A business continuity plan (BCP) differs from a disaster recovery plan (DRP) in that the BCP primarily focuses on:
20An organization is implementing a patch management process. Which of the following is the most critical step to ensure that patches do not disrupt critical business operations?
21Which digital forensics tool is specifically designed for memory forensics?
22A security analyst is reviewing SIEM logs and notices multiple failed login attempts from a single IP address followed by a successful login. The account belongs to a user in finance. Which incident category is most appropriate?
23What is the primary purpose of a Change Advisory Board (CAB) in change management?
24An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)
25A company is evaluating disaster recovery strategies and wants to minimize both RTO and RPO. Which THREE options provide the best combination of low RTO and low RPO? (Select THREE)
26Which of the following best describes the primary purpose of an incident response plan?
27During a digital forensics investigation, which of the following data sources has the highest order of volatility?
28An organization has a maximum tolerable downtime (MTD) of 8 hours for its critical e-commerce platform. The recovery time objective (RTO) is set to 4 hours, and the recovery point objective (RPO) is 30 minutes. Which disaster recovery strategy is most cost-effective while meeting these requirements?
29Which of the following is the primary purpose of a Change Advisory Board (CAB)?
30What type of DLP system monitors data in motion across the network?
31An organization's security operations center (SOC) uses a SIEM to correlate logs. The SOC manager wants to automate response actions for low-severity alerts. Which technology would best support this goal?
32During a forensic investigation, the investigator must ensure that evidence is properly handled and documented. What is the primary purpose of maintaining a chain of custody?
33An organization is designing its incident response team roles. Which role is primarily responsible for collecting and preserving evidence for legal proceedings?
34Which of the following is an example of a social engineering attack?
35An organization wants to ensure that its critical database can be restored to a point within the last 15 minutes in case of failure. Which metric defines this requirement?
36Which of the following is the most important factor when prioritizing vulnerability remediation in a vulnerability management program?
37A SOC analyst at Tier 1 identifies a potential malware infection on a user workstation. What is the next step in the standard incident response process?
38A security analyst is selecting forensic tools for an investigation. Which TWO tools are best suited for memory forensics? (Select TWO.)
39An organization is planning its disaster recovery strategy. Which THREE options are considered recovery site types? (Select THREE.)
40An organization is developing an incident response plan. Which component is primarily responsible for defining the criteria for escalating an incident to senior management and legal counsel?
41During a forensic investigation, an analyst must collect volatile data in the correct order. Which of the following sequences correctly follows the order of volatility?
42An organization has a maximum tolerable downtime (MTD) of 8 hours for a critical application. The recovery time objective (RTO) is set to 4 hours. Which of the following best describes the purpose of the RTO?
43A company plans to implement a disaster recovery site that can be operational within 2 hours of a failure. Which type of DR site best meets this requirement?
44Which type of digital forensics involves capturing and analyzing network traffic to investigate a security incident?
45A security team implements a Data Loss Prevention (DLP) solution to monitor email attachments for sensitive data. Which type of DLP is being used?
46Which of the following is a key difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
47A security analyst is identifying incident categories for a new incident response plan. Which TWO of the following are valid incident categories according to standard IR frameworks?
48During a forensic investigation, which TWO of the following are essential steps to maintain chain of custody?
49A company is selecting a disaster recovery strategy for a mission-critical application. Which TWO of the following strategies provide the shortest recovery time objective (RTO)?
50A SOC manager is designing a tiered incident response team. Which THREE of the following are standard roles in an incident response team according to industry best practices?
51A security analyst is configuring a SIEM to improve threat detection. Which THREE of the following are essential capabilities of a SIEM system?
52A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?
53A security administrator is reviewing the logging configuration for a fleet of Linux servers that host a regulated payment application. An external auditor requires that the servers produce a tamper-evident record of all authentication events, including successful and failed logons, and that the record be retained for one year. Which action BEST satisfies the auditor's requirement?
54A hospital's security operations center receives an alert that a nurse's workstation is communicating with a known command-and-control IP address. The analyst confirms the workstation is infected with malware that is beaconing every sixty seconds. Following the incident response process, which action should the analyst take FIRST?
Be able to read a scenario and classify it: incident type, correct IR role, right BCP/DR metric, or best remediation priority. The single most important thing is matching the question's ask (detect, respond, recover, or prioritize) to the correct concept, not the most technical answer.
The Courseiva CISSP question bank contains 54 questions in the Security Operations domain, covering the 13% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Operations domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included