Courseiva
Security Operations →easyMultiple Choice

ISC2 CC Security Operations Practice Question

A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?

⚠ Common exam trap

The trap is assuming that because the alert looks serious (unusual geography, successful login), it should go straight to Tier 2 or Tier 3 — but all alerts enter through Tier 1 triage first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tier 1 analyst

Tier 1 analysts are responsible for initial alert triage — monitoring the SIEM queue, validating alerts, gathering basic context, and escalating confirmed incidents to Tier 2. The scenario describes a standard alert requiring first-level review, which falls squarely within Tier 1 duties. Escalation to higher tiers occurs only after Tier 1 confirms the incident or determines it requires deeper investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Tier 1 analyst

    Why this is correct

    Tier 1 analysts handle initial alert triage, validating whether the failed logins followed by an anomalous successful login represent a genuine incident before escalation. This monitoring and classification duty sits squarely within Tier 1 responsibilities, with Tier 2 and Tier 3 engaged only after triage confirms escalation is warranted.

  • ✗

    IT support team

    Why it's wrong here

    IT support manages user accounts and endpoints, not SIEM alert triage, which sits with the SOC. It is tempting because IT support would eventually reset the compromised account, but that remediation action follows SOC detection and escalation, not the initial triage step.

  • ✗

    Tier 2 analyst

    Why it's wrong here

    Tier 2 handles deeper investigation and incident response, not initial alert triage, which is Tier 1's defined responsibility. It is tempting because Tier 2 does perform triage, but only for escalated or complex incidents that Tier 1 has already assessed and passed upward.

  • ✗

    Tier 3 analyst

    Why it's wrong here

    Tier 3 handles deep incident investigation, threat hunting and remediation, not first-pass alert triage. It is tempting because the unusual-geography login looks severe, but Tier 3 is the correct choice only once Tier 1 triage confirms a genuine incident requiring advanced analysis.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.