Courseiva
hardMultiple ChoiceObjective-mapped

CISM Practice Question: A security operations center (SOC) analyst…

A security operations center (SOC) analyst receives an alert from the SIEM indicating a potential command and control (C2) communication. The alert is based on a signature that matches known C2 traffic. What is the MOST appropriate next step?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify the alert by correlating with other log sources

Verifying the alert by checking other log sources (e.g., firewall, DNS) reduces false positives before escalating. Escalating immediately (B) may waste resources if the alert is a false positive. Blocking the IP address at the firewall (A) could be premature if the traffic is legitimate. Running a full antivirus scan on all endpoints (D) is a reactive step that does not address the immediate investigation of the alert.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Block the destination IP address at the firewall

    Why it's wrong here

    Blocking without confirmation could disrupt legitimate traffic.

  • Escalate the alert to the incident response team immediately

    Why it's wrong here

    Escalation without verification may cause unnecessary work.

  • Verify the alert by correlating with other log sources

    Why this is correct

    Correlation with other logs confirms if it's a true positive.

  • Perform a full antivirus scan on all endpoints

    Why it's wrong here

    Antivirus scan is a reactive measure, not investigative.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.