200-201 Security Policies and Procedures Practice Question
Which SOC tier is responsible for threat hunting and advanced forensic analysis?
⚠ Common exam trap
Test-takers frequently confuse Tier 2's incident response duties with Tier 3's proactive threat hunting and forensic analysis — candidates often pick Tier 2 because it sounds 'advanced' enough.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tier 3
Tier 3 SOC analysts are the most senior and are responsible for advanced threat hunting, malware reverse engineering, and deep forensic analysis. Tier 1 handles initial triage and alert monitoring, while Tier 2 performs deeper investigation and incident response. Threat hunting and forensics are explicitly Tier 3 responsibilities in the standard SOC tier model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tier 1
Why it's wrong here
Tier 1 analysts triage and monitor alerts, escalating incidents rather than performing proactive threat hunting or advanced forensic analysis, which sit with Tier 3. It is tempting because Tier 1 is the entry point for incident handling, and it would be the correct choice for initial alert triage and ticket creation.
- ✓
Tier 3
Why this is correct
Tier 3 analysts handle proactive threat hunting and deep forensic investigation, the highest analytical escalation level. Tier 1 performs triage and monitoring, Tier 2 handles incident response escalation; advanced forensics and hunting sit with Tier 3, matching the responsibilities named in the question.
- ✗
All tiers equally
Why it's wrong here
Threat hunting and advanced forensics require the specialist skills concentrated in Tier 3, so distributing them across all tiers removes the dedicated expertise the scenario needs. It is tempting as a collaborative ideal, and would fit a flat, small SOC where every analyst genuinely rotates through all duties.
- ✗
Tier 2
Why it's wrong here
Tier 2 handles escalated incident investigation and remediation, not proactive hunting or deep forensics, which sit with Tier 3. It is tempting because Tier 2 does perform analysis beyond Tier 1 triage, so it would be correct for investigating alerts escalated from Tier 1 monitoring.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.