CISM Information Security Programme Practice Question
What is the primary function of a Security Operations Center (SOC)?
⚠ Common exam trap
CISM often tests the boundary between operational security functions (SOC monitors and responds) and governance/design functions (architecture, policy), so candidates who associate 'security' broadly with the SOC pick options A or B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Continuous monitoring, detection, and response to security threats
A SOC's primary mission is continuous monitoring of security telemetry, detecting threats, and coordinating response actions. It operates 24/7 using SIEM, EDR, and threat intelligence to identify and triage incidents in real time. This detection-and-response focus distinguishes the SOC from architecture, policy, or training functions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Designing the security architecture
Why it's wrong here
Security architecture design is performed by architecture and engineering teams, not the SOC. It is tempting because SOC staff understand threats and controls deeply, but their function is continuous monitoring, detection, triage and incident response rather than designing controls.
- ✗
Developing security policies and standards
Why it's wrong here
Policy and standards development is a governance function owned by security management and architecture, not the SOC. It is tempting because the SOC informs policy through incident findings, but its operational role is monitoring, detection and response.
- ✗
Conducting security awareness training
Why it's wrong here
A SOC's function is continuous monitoring, detection and response to security events, so awareness training belongs to a separate security education programme. It is tempting because awareness training is a genuine security control, and would be the right answer if the question asked how to reduce phishing susceptibility across staff.
- ✓
Continuous monitoring, detection, and response to security threats
Why this is correct
A SOC's core purpose is round-the-clock visibility: correlating telemetry, detecting anomalous activity and orchestrating response. This continuous monitoring and response capability distinguishes it from governance, architecture or compliance functions, directly satisfying the stem's demand for the primary operational function.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.