Courseiva

200-201 Security Policies and Procedures Practice Question

A SOC Tier 1 analyst is processing alerts. Which THREE tasks are typical for a Tier 1 analyst? (Select three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Execute basic investigation using standard tools

Option C is correct because Tier 1 analysts perform basic investigations with standard tools such as SIEM queries, log review, and endpoint/EDR lookups to validate alerts before escalation. Option D is correct because continuous monitoring of alerts and events from sources like SIEM, IDS/IPS, and EDR is a core Tier 1 responsibility. Option E is correct because initial triage and categorization—confirming true/false positive, assigning severity, and routing to the right queue—is exactly the Tier 1 role. Option A does not belong because deep malware analysis (reverse engineering, sandboxing, code disassembly) is typically Tier 2/Tier 3 or a dedicated malware analyst function. Option B does not belong because developing new detection signatures or rules is an engineering/detection-content task, not a Tier 1 monitoring and triage duty.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct deep malware analysis

    Why it's wrong here

    Deep malware analysis is a Tier 2 or Tier 3 responsibility involving reverse engineering and sandbox tooling. Tier 1 performs initial triage, enrichment and escalation. It is tempting because Tier 1 analysts examine suspicious files, but full behavioural analysis demands specialist skills and isolated environments beyond first-line scope.

  • ✗

    Develop new detection signatures

    Why it's wrong here

    Signature development belongs to Tier 2 or detection engineering, who own rule creation and tuning. Tier 1 triages, validates and escalates alerts using existing detections. It is tempting because Tier 1 analysts see alert gaps daily, but authoring signatures requires tooling access and testing authority outside their remit.

  • ✓

    Execute basic investigation using standard tools

    Why this is correct

    Tier 1 performs basic investigation with standard tooling such as SIEM queries and signature lookups, gathering enough evidence to confirm or dismiss an alert before escalating. Deeper forensics and remediation remain Tier 2 or Tier 3 responsibilities.

  • ✓

    Monitor alerts and events

    Why this is correct

    Continuous monitoring of alerts and events is the core Tier 1 function, watching the SIEM queue and consoles for triggered detections. This satisfies the scenario's requirement that the analyst processes incoming alerts rather than performing engineering or threat hunting.

  • ✓

    Perform initial triage and categorization

    Why this is correct

    Initial triage and categorisation is Tier 1 work: validating the alert, assigning severity and classifying the incident type so it routes correctly. This satisfies the scenario's requirement to process alerts before escalation to Tier 2.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.