ISC2 CC Security Operations Practice Question
A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?
⚠ Common exam trap
The trap is assuming that because the alert looks serious (unusual geography, successful login), it should go straight to Tier 2 or Tier 3 — but all alerts enter through Tier 1 triage first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tier 1 analyst
Tier 1 analysts are responsible for initial alert triage — monitoring the SIEM queue, validating alerts, gathering basic context, and escalating confirmed incidents to Tier 2. The scenario describes a standard alert requiring first-level review, which falls squarely within Tier 1 duties. Escalation to higher tiers occurs only after Tier 1 confirms the incident or determines it requires deeper investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Tier 1 analyst
Why this is correct
Tier 1 analysts handle initial alert triage, validating whether the failed logins followed by an anomalous successful login represent a genuine incident before escalation. This monitoring and classification duty sits squarely within Tier 1 responsibilities, with Tier 2 and Tier 3 engaged only after triage confirms escalation is warranted.
- ✗
IT support team
Why it's wrong here
IT support manages user accounts and endpoints, not SIEM alert triage, which sits with the SOC. It is tempting because IT support would eventually reset the compromised account, but that remediation action follows SOC detection and escalation, not the initial triage step.
- ✗
Tier 2 analyst
Why it's wrong here
Tier 2 handles deeper investigation and incident response, not initial alert triage, which is Tier 1's defined responsibility. It is tempting because Tier 2 does perform triage, but only for escalated or complex incidents that Tier 1 has already assessed and passed upward.
- ✗
Tier 3 analyst
Why it's wrong here
Tier 3 handles deep incident investigation, threat hunting and remediation, not first-pass alert triage. It is tempting because the unusual-geography login looks severe, but Tier 3 is the correct choice only once Tier 1 triage confirms a genuine incident requiring advanced analysis.
Go deeper
Related to this question
Learn chapter
Security Operations Basics
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.