Courseiva

CCNA Security Operations And Management Questions

16 questions · Security Operations And Management · All types, answers revealed

1
Multi-Selecthard

Which THREE techniques are commonly used by SOC teams to improve alert quality and reduce fatigue?

Select 3 answers
A.Alert aggregation
B.Removing the SOC Tier 1 analysts
C.Suppression of known-good patterns
D.Rule tuning based on historical data
E.Increasing the volume of log ingestion
AnswersA, C, D

Reduces volume of individual tickets.

Why this answer

Tuning, aggregation, and suppression are the core methods for refining alert volume and signal-to-noise ratios.

2
Multi-Selecthard

Which THREE components are essential to include in a SOC Incident Response plan?

Select 3 answers
A.Defined roles and responsibilities
B.Physical security building permits
C.Communication escalation matrix
D.List of office vacation days
E.Standard Operating Procedures (SOPs)
AnswersA, C, E

Essential to prevent task duplication.

Why this answer

An effective IR plan must include communication protocols, clear roles, and defined procedures for handling incidents.

3
Multi-Selectmedium

Which TWO factors are most critical when calculating the ROI of a SOC?

Select 2 answers
A.Cost of potential data breach incidents
B.Total cost of security personnel and tools
C.Number of social media followers
D.Office space square footage
E.Number of coffee machines in the SOC
AnswersA, B

This defines the value of the SOC.

Why this answer

ROI in a SOC is calculated by comparing the reduction in risk (potential cost of breach) and the operational costs (tools/personnel).

4
MCQmedium

Which activity is a primary responsibility of a Threat Intelligence analyst within the SOC?

A.Hardening server images
B.Updating correlation rules based on new IOCs
C.Managing SOC budget
D.Writing compliance reports
AnswerB

This operationalizes the intelligence.

Why this answer

Integrating external threat feeds to update correlation rules is a core function of threat intelligence within operations.

5
MCQmedium

Your organization is evaluating its SOC maturity using the CMMI-based model. If the SOC has documented standard processes but lacks consistent automation, which maturity level has been achieved?

A.Level 3
B.Level 5
C.Level 2
D.Level 1
AnswerA

Level 3 requires standardized processes.

Why this answer

Level 3 (Defined) indicates processes are established and documented, but not yet optimized.

6
MCQhard

You are auditing your SOC workflow and find that incident escalations are delayed. Which metric should you analyze to identify the bottleneck between alert detection and analyst assignment?

A.MTTR
B.False Positive Rate
C.Dwell Time
D.MTTA
AnswerD

MTTA tracks the latency in alert pickup.

Why this answer

Mean Time to Acknowledge (MTTA) specifically measures the time from alert generation to human intervention.

7
MCQmedium

A SOC is implementing a 'Follow-the-Sun' model. What is the most critical requirement for this transition to be successful?

A.Purchasing a new SIEM license
B.Moving all logs to the cloud
C.Increasing the number of Tier 3 analysts
D.Standardized handover and documentation
AnswerD

Handover is essential for continuity.

Why this answer

Standardization of playbooks and handoff procedures ensures continuity across different time zones.

8
MCQeasy

Which SOC service model involves an organization outsourcing its security monitoring to a third-party provider while retaining internal control?

A.MSSP
B.Virtual SOC
C.Internal SOC
D.Hybrid Cloud SOC
AnswerA

MSSP is the standard outsourcing model.

Why this answer

Managed Security Service Provider (MSSP) models allow outsourcing while maintaining operational oversight.

9
MCQeasy

A SOC manager is defining the tiered structure of the SOC. Which tier is primarily responsible for initial triage and basic incident filtering?

A.Tier 3
B.SOC Manager
C.Tier 1
D.Tier 2
AnswerC

Tier 1 is the front line for alert triage.

Why this answer

Tier 1 analysts perform the initial monitoring, triage, and basic categorization of alerts.

10
Multi-Selectmedium

Which TWO actions should an analyst take when reviewing an alert that has been flagged as a 'False Positive' in the SIEM?

Select 2 answers
A.Ignore the alert without closure
B.Document the rationale for closure
C.Delete the original event log
D.Update the correlation rule logic
E.Request a new SIEM license
AnswersB, D

Ensures auditability.

Why this answer

Proper handling of false positives involves documenting the finding and updating the rule to prevent re-occurrence.

11
MCQeasy

What is the primary goal of the 'Eradication' phase in the Incident Response lifecycle?

A.Identifying the source
B.Eliminating the threat
C.Blocking traffic
D.Restoring backups
AnswerB

Eradication removes the threat completely.

Why this answer

Eradication is intended to remove the root cause and all remnants of the threat from the environment.

12
MCQmedium

You are configuring a SIEM alert threshold to reduce noise. Which metric should you adjust to ensure that only events occurring 5 times within a 60-second window trigger a high-severity alert?

A.Event Parser Configuration
B.Correlation Rule Threshold
C.Aggregation Key
D.Suppression Window
AnswerB

This allows setting frequency and time constraints.

Why this answer

A threshold configuration with a count and a time window is the standard approach for rate-limiting alerts.

13
MCQhard

You are configuring a SIEM to integrate with an EDR tool. Which data field is most important for cross-platform correlation when tracking a single user's activity across the network?

A.Timestamp
B.Device Name
C.Source IP
D.UPN
AnswerD

UPN is a unique identity anchor.

Why this answer

The UPN (User Principal Name) or SID provides the unique identifier needed for correlating activity across multiple disparate systems.

14
Multi-Selectmedium

Which TWO metrics are essential for measuring the efficiency of an incident response team?

Select 2 answers
A.Number of emails sent to stakeholders
B.Mean Time to Respond (MTTR)
C.Average salary of analysts
D.Building security badge access logs
E.Incident volume per analyst
AnswersB, E

Direct measure of response speed.

Why this answer

MTTR and total number of incidents handled are standard metrics for operational efficiency.

15
MCQeasy

Which role is responsible for the ongoing tuning of correlation rules and maintaining the SIEM health in a mature SOC?

A.Security Content Engineer
B.Incident Responder
C.Compliance Officer
D.SOC Manager
AnswerA

This role focuses on SIEM rules and tuning.

Why this answer

The SOC Engineer manages the underlying SIEM infrastructure and rule efficacy.

16
MCQhard

During incident lifecycle management, your team needs to transition from 'Detection' to 'Containment'. What is the most critical action to perform first within your SOAR platform's playbook?

A.Reset all user passwords
B.Perform full forensic imaging
C.Run host isolation playbook
D.Update the firewall rule base
AnswerC

Isolation is the primary containment step.

Why this answer

Isolating the affected asset prevents lateral movement before moving to eradication.

Ready to test yourself?

Try a timed practice session using only Security Operations And Management questions.