hardMultiple Select
ISC2 CC Practice Question: Is planning to implement a security operations…
An organization is planning to implement a security operations center (SOC) and is considering different monitoring strategies. Which THREE of the following are essential components of a tiered SOC model? (Choose three.)
⚠ Common exam trap
ISC2 often tests the distinction between SOC tiers and supporting roles; the trap here is that candidates mistake management or intelligence functions as part of the tiered analyst hierarchy, when only Tier 1, Tier 2, and Tier 3 analysts constitute the core escalation model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tier 2 analysts who conduct in-depth analysis and incident response
The tiered SOC model is built around escalating analyst responsibilities, so option D is correct because Tier 1 analysts are the first line of defense, continuously monitoring SIEM alerts and performing initial triage to filter false positives before escalation. Option C is correct because Tier 2 analysts take escalated incidents, conduct in-depth analysis, correlate events across multiple data sources, and drive the incident response process. Option E is correct because Tier 3 analysts handle the most complex work, including proactive threat hunting, advanced digital forensics, and malware reverse engineering, often feeding new detection logic back to lower tiers. Options A and B are not essential components of the tiered analyst structure itself: a SOC manager is an administrative/leadership role rather than a tier, and a dedicated threat intelligence team is a supporting function that may be separate from or feed into the tiered model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A SOC manager who oversees daily operations and reporting
Why it's wrong here
A SOC manager is a leadership role, not a tier within the tiered SOC model. The tiers themselves are Tier 1 triage, Tier 2 investigation and Tier 3 threat hunting or advanced response. A SOC manager would be the correct choice if the question asked about governance, staffing or operational oversight roles.
- ✗
A dedicated threat intelligence team that provides context on indicators
Why it's wrong here
A dedicated threat intelligence team is an intelligence function, not a tier within the tiered SOC model. Tiered SOCs are structured around Tier 1 triage, Tier 2 investigation and Tier 3 hunting or response. Threat intelligence would be correct if the question asked which supporting capability enriches detections with indicator context.
- ✓
Tier 2 analysts who conduct in-depth analysis and incident response
Why this is correct
Tier 2 provides the escalation layer where alerts triaged by Tier 1 receive deeper investigation, correlation and containment. Without this escalation capability, incidents stall at triage, so it is essential to a tiered SOC model.
- ✓
Tier 1 analysts who monitor alerts and perform initial triage
Why this is correct
Tier 1 is the first line of defence, continuously monitoring alert queues and performing initial triage to filter false positives before escalation. This filtering function is fundamental to the tiered SOC model's division of labour.
- ✓
Tier 3 analysts who focus on threat hunting and advanced forensics
Why this is correct
Tier 3 analysts handle proactive threat hunting and deep forensic investigation, the escalation point when Tier 1 triage and Tier 2 incident response cannot resolve an incident. This satisfies the stem's requirement for a tiered SOC model, where each tier has distinct escalation responsibilities rather than duplicated monitoring duties.
Go deeper
Related to this question
Learn chapter
Security Operations Basics
Key term
Role
A role is a named set of permissions that can be assigned to users or groups to control access to resources in an IT environment.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.