Courseiva

200-201 Security Policies and Procedures Practice Question

Which SOC tier is responsible for threat hunting and advanced forensic analysis?

⚠ Common exam trap

Test-takers frequently confuse Tier 2's incident response duties with Tier 3's proactive threat hunting and forensic analysis — candidates often pick Tier 2 because it sounds 'advanced' enough.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tier 3

Tier 3 SOC analysts are the most senior and are responsible for advanced threat hunting, malware reverse engineering, and deep forensic analysis. Tier 1 handles initial triage and alert monitoring, while Tier 2 performs deeper investigation and incident response. Threat hunting and forensics are explicitly Tier 3 responsibilities in the standard SOC tier model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Tier 1

    Why it's wrong here

    Tier 1 analysts triage and monitor alerts, escalating incidents rather than performing proactive threat hunting or advanced forensic analysis, which sit with Tier 3. It is tempting because Tier 1 is the entry point for incident handling, and it would be the correct choice for initial alert triage and ticket creation.

  • ✓

    Tier 3

    Why this is correct

    Tier 3 analysts handle proactive threat hunting and deep forensic investigation, the highest analytical escalation level. Tier 1 performs triage and monitoring, Tier 2 handles incident response escalation; advanced forensics and hunting sit with Tier 3, matching the responsibilities named in the question.

  • ✗

    All tiers equally

    Why it's wrong here

    Threat hunting and advanced forensics require the specialist skills concentrated in Tier 3, so distributing them across all tiers removes the dedicated expertise the scenario needs. It is tempting as a collaborative ideal, and would fit a flat, small SOC where every analyst genuinely rotates through all duties.

  • ✗

    Tier 2

    Why it's wrong here

    Tier 2 handles escalated incident investigation and remediation, not proactive hunting or deep forensics, which sit with Tier 3. It is tempting because Tier 2 does perform analysis beyond Tier 1 triage, so it would be correct for investigating alerts escalated from Tier 1 monitoring.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.