ISC2 CC Security Operations Practice Question
A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a deeper investigation to identify affected systems and data.
Tier 2 analysts conduct deeper investigation to determine the scope and impact of a confirmed incident before initiating response actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Escalate the alert to Tier 3 for advanced analysis.
Why it's wrong here
Tier 2 is responsible for deeper investigation; Tier 3 is for advanced analysis and threat hunting.
- ✓
Conduct a deeper investigation to identify affected systems and data.
Why this is correct
Tier 2 investigates to understand the incident's scope and impact.
- ✗
Block the external IP address at the firewall immediately.
Why it's wrong here
Immediate blocking may disrupt investigation and evidence collection; deeper analysis is needed first.
- ✗
Reboot the server to terminate any malicious processes.
Why it's wrong here
Rebooting may destroy volatile evidence and not fully remediate.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
False positive
A false positive is an alert or result that indicates a security threat or vulnerability exists when in fact there is no real issue.
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
About these practice questions
Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.