Courseiva

CS0-004 · topic practice

Security Operations practice questions

Security Operations covers monitoring, detection, and response using tools like SIEM, EDR, and network analysis. You will interpret alerts, telemetry, and packet captures to identify malicious activity such as C2 beaconing, malicious document execution, and exploit attempts, then decide on containment, escalation, and remediation actions based on evidence.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Operations

What the exam tests

What to know about Security Operations

You must be able to read telemetry and packet data, correlate process ancestry with network activity, and judge whether an alert is a true positive. The most important skill is linking evidence across sources before choosing containment, escalation, or closure.

Analyzing DNS query patterns to detect DGA and command-and-control beaconing behavior

Correlating EDR process trees, parent-child relationships, and network connections for threat hunting

Triaging suspicious process execution like Office spawning PowerShell to identify phishing payloads

Evaluating vulnerability scan findings against compensating controls such as WAF and CVSS context

Watch out for

Common Security Operations exam traps

  • ▸Treating a high CVSS score as automatically exploitable without checking compensating controls, exposure, and attack vector reachability
  • ▸Assuming any PowerShell execution is malicious instead of examining parent process, command-line arguments, and network behavior
  • ▸Ignoring process lineage and user context when triaging EDR alerts, leading to missed or misclassified true positives

Practice set

Security Operations questions

20 questions · select your answer, then reveal the explanation

During a memory analysis of a compromised host, an analyst finds that 'svchost.exe' is running from 'C:\Users\Public\svchost.exe' instead of 'C:\Windows\System32\svchost.exe'. The process has injected code into a legitimate 'explorer.exe' process. What technique is being observed?

An analyst is reviewing logs from multiple sources and sees that a user logged into a workstation at 8:00 AM, then the same user logged into a server in a different building at 8:01 AM. The authentication logs show the same source IP for both logins. What should the analyst suspect?

During a network traffic analysis, a security analyst observes repeated connections from an internal host to an external IP address on TCP port 53. The traffic volume is low but consistent. What type of anomaly is most likely indicated?

A security analyst is tuning a SIEM rule that generates alerts for any failed login attempt. The rule produces too many alerts, overwhelming the team. Which TWO actions would most effectively reduce false positives while maintaining detection of actual brute-force attacks?

A threat hunter notices that a legitimate Windows binary 'rundll32.exe' is executing with network connections to an external IP address. The parent process is 'winword.exe'. Which LOLBin technique is most likely being used?

A vulnerability scan report shows a critical finding with a CVSS score of 9.8. The system is a web server behind a WAF that blocks the attack vector. What should the analyst do?

During an incident response, an analyst identifies suspicious registry modifications in the 'Run' key and a scheduled task that executes a script. Which three persistence mechanisms are most likely being used? (Choose three.)

An analyst is creating a detection rule for lateral movement using SMB. Which two network indicators should be included in the rule? (Choose two.)

A security analyst is investigating an alert from an endpoint EDR that shows a process with a parent-child relationship where the parent is Microsoft Word and the child process is wscript.exe executing a command to download a PowerShell script. Which MITRE ATT&CK technique does this likely represent?

A security analyst is configuring a vulnerability scanner to evaluate the security posture of internal servers. Which type of scan provides the most accurate assessment of missing patches?

Question 11mediummultiple choice
Read the full DNS explanation →

During a threat hunt, an analyst notices repeated DNS queries for random-looking subdomains under a legitimate domain. The domains have high entropy and never existed before. What technique is most likely being used?

An analyst is reviewing a memory dump from a compromised workstation and finds a process that appears to be a legitimate system process but has a different parent process and is running from a non-standard location. Which analysis technique is most appropriate?

Question 13mediummulti select
Read the full DNS explanation →

A security analyst is investigating a potential data exfiltration using DNS. Which TWO indicators are most consistent with DNS tunneling?

A threat hunter is using osquery to look for persistence mechanisms on a set of Windows endpoints. Which THREE registry keys or scheduled tasks should the hunter check for common persistence?

An analyst is triaging a SIEM alert that fires when a single host makes more than 100 outbound connections to unique IPs within one minute. The analyst finds that the host is a web server responding to legitimate client requests. What is the best action to reduce false positives?

During a threat hunt, an analyst is looking for signs of lateral movement using pass-the-hash. Which three of the following log sources would be most useful for detecting this technique?

An analyst is investigating a potential data exfiltration incident. The analyst observes repeated HTTPS connections to a cloud storage provider from a server that does not normally use that service. Which three additional artifacts would strengthen the case for exfiltration?

A SOC analyst receives an alert from the SIEM indicating a high volume of outbound traffic from a single workstation to an IP address in a country where the organization does no business. The alert is based on a rule that triggers when outbound traffic exceeds 1 GB in 5 minutes. Upon investigation, the analyst finds that the workstation is used by a developer who downloaded a large dataset from a cloud storage service. Which action should the analyst take to improve the alert's accuracy without disabling it entirely?

During a traffic analysis, a security analyst notices repeated TCP SYN packets sent to an internal server from an external IP, but the server never responds with SYN-ACK. The external IP sends a new SYN packet every 30 seconds. What does this behavior most likely indicate?

Question 20hardmultiple choice
Read the full DNS explanation →

A security analyst is reviewing DNS logs and notices that a workstation is making frequent queries to domains with random-looking strings, such as 'a3b9f2d1.example.com'. These domains resolve to different IP addresses each time. Which type of activity is most likely being observed?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Operations sessions

Start a Security Operations only practice session

Every question in these sessions is drawn from the Security Operations domain — nothing else.

Related practice questions

Related CS0-004 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CS0-004 exam test about Security Operations?
You must be able to read telemetry and packet data, correlate process ancestry with network activity, and judge whether an alert is a true positive. The most important skill is linking evidence across sources before choosing containment, escalation, or closure.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Operations questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Operations domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CS0-004 topics?
Use the topic links above to move to related areas, or go back to the CS0-004 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CS0-004 exam covers. They are not copied from any real exam or dump site.