Courseiva

ISC · topic practice

Security Operations practice questions

Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Security Operations practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Security Operations

What the exam tests

What to know about Security Operations

Security Operations questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Operations exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Security Operations questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Ansible explanation →

An organization uses Microsoft Sentinel. To ensure that an automated incident response playbook only triggers when a high-severity alert originates from a specific production subnet, where should the condition be defined?

In an incident response plan, which metric is most useful for measuring the 'dwell time' of a threat actor?

Which document is considered the primary 'source of truth' for defining the SOC's roles, responsibilities, and communication paths during a major security incident?

When using Palo Alto Networks Cortex XSOAR, which component is responsible for orchestrating the execution of scripts across multiple third-party integrations?

An organization is investigating a potential lateral movement incident in AWS. Which CloudTrail event field provides the most reliable indicator of the source IP address for an API call performed by an IAM role?

When configuring CrowdStrike Falcon to isolate a host during an active incident, what is the prerequisite requirement for the agent's communication state?

In Tenable.io, when prioritizing vulnerability remediation, which metric provides the best insight into the likelihood of a vulnerability being exploited in the wild?

In Splunk Enterprise Security, which dashboard should the SOC manager review to evaluate the effectiveness of the current correlation searches and the volume of notable events?

When analyzing network traffic in Wireshark for potential exfiltration, what specific filter allows you to isolate TCP traffic where the payload size exceeds 10MB?

Which phase of the NIST Incident Response Life Cycle involves activities like system sanitization and validation of system integrity?

In Okta, to restrict administrative access to a specific geographic region during an active session, which policy should be modified?

When configuring a Cisco ASA firewall to log deny events to a remote Syslog server, what is the minimum logging level required to ensure that denied packets are captured?

In VMware Carbon Black Cloud, which feature should be enabled to block unauthorized scripts while allowing signed binaries from trusted software vendors?

Which SOC metric is most appropriate to present to executive leadership to demonstrate the business value of security investments?

A security analyst is troubleshooting a failed connection to an internal application that is protected by Zscaler Private Access (ZPA). Which tool should the analyst use to verify if the policy is blocking the request?

Which component in the MITRE ATT&CK framework should be mapped to an SOC alerting rule to ensure the alert covers a specific adversary objective?

When managing a FortiGate firewall, which feature allows the SOC to dynamically update network objects based on external threat feeds?

A Microsoft Entra ID (Azure AD) user account is suspected of compromise. What is the most effective way to invalidate all active session tokens immediately?

In Rapid7 InsightVM, what is the best way to categorize assets into groups based on their business function for targeted vulnerability reporting?

When implementing FIM (File Integrity Monitoring) in Tripwire Enterprise, what is the specific purpose of a 'Promotion' action?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Operations sessions

Start a Security Operations only practice session

Every question in these sessions is drawn from the Security Operations domain — nothing else.

Related practice questions

Related ISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the ISC exam test about Security Operations?
Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Operations questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Operations domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other ISC topics?
Use the topic links above to move to related areas, or go back to the ISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the ISC exam covers. They are not copied from any real exam or dump site.