Courseiva

CISM Information Security Programme Practice Question

In designing a security operations centre (SOC), which TWO functions are core to the SOC's responsibilities? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security monitoring and detection

Option B, security monitoring and detection, is a core SOC responsibility because the SOC's primary mission is continuous 24x7 visibility over logs, network traffic, and endpoint telemetry using SIEM, IDS/IPS, and EDR to identify malicious activity. Option E, incident response, is also core because once detection occurs, the SOC triages, contains, eradicates, and recovers from incidents, coordinating escalation and forensic evidence handling. Together, monitoring/detection and incident response form the detect-and-respond loop that defines SOC operations. Vulnerability management (A) is typically owned by a vulnerability management or risk team, though the SOC may consume its output. Security awareness training (C) belongs to the security awareness/HR function, and security architecture design (D) is an engineering/architecture responsibility rather than a SOC operational function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vulnerability management

    Why it's wrong here

    Vulnerability management scans and remediates weaknesses, but the SOC's core remit is detecting, analysing and responding to incidents in real time. It suits a dedicated vulnerability-management programme, not the SOC's continuous monitoring and response function.

  • ✓

    Security monitoring and detection

    Why this is correct

    Security monitoring and detection is a core SOC function because it continuously collects and analyses telemetry to identify threats against organisational assets. This satisfies the stem's requirement for core responsibilities, distinguishing day-to-day detection operations from governance, architecture or compliance activities owned elsewhere in the security organisation.

  • ✗

    Security awareness training

    Why it's wrong here

    Training builds user awareness across the workforce; it does not monitor, detect or respond to events, which are the SOC's operational remit. It is tempting because awareness reduces phishing and human-error incidents, so it is genuinely a security control — but it sits with HR or the awareness programme, not the SOC's monitoring and incident-response functions.

  • ✗

    Security architecture design

    Why it's wrong here

    Security architecture design defines controls and system structure up front; it is an engineering and governance activity, not continuous SOC monitoring and incident response. It suits designing a new secure system, not running the SOC's detection and response operations.

  • ✓

    Incident response

    Why this is correct

    Incident response is a core SOC function because it contains, eradicates and recovers from detected security incidents, limiting business impact. This satisfies the stem's requirement for core responsibilities, distinguishing hands-on operational response from strategic functions such as policy ownership, risk governance or security architecture design.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.