Courseiva
hardMultiple Select

ISC2 CC Practice Question: Is planning to implement a security operations…

An organization is planning to implement a security operations center (SOC) and is considering different monitoring strategies. Which THREE of the following are essential components of a tiered SOC model? (Choose three.)

⚠ Common exam trap

ISC2 often tests the distinction between SOC tiers and supporting roles; the trap here is that candidates mistake management or intelligence functions as part of the tiered analyst hierarchy, when only Tier 1, Tier 2, and Tier 3 analysts constitute the core escalation model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tier 2 analysts who conduct in-depth analysis and incident response

The tiered SOC model is built around escalating analyst responsibilities, so option D is correct because Tier 1 analysts are the first line of defense, continuously monitoring SIEM alerts and performing initial triage to filter false positives before escalation. Option C is correct because Tier 2 analysts take escalated incidents, conduct in-depth analysis, correlate events across multiple data sources, and drive the incident response process. Option E is correct because Tier 3 analysts handle the most complex work, including proactive threat hunting, advanced digital forensics, and malware reverse engineering, often feeding new detection logic back to lower tiers. Options A and B are not essential components of the tiered analyst structure itself: a SOC manager is an administrative/leadership role rather than a tier, and a dedicated threat intelligence team is a supporting function that may be separate from or feed into the tiered model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A SOC manager who oversees daily operations and reporting

    Why it's wrong here

    A SOC manager is a leadership role, not a tier within the tiered SOC model. The tiers themselves are Tier 1 triage, Tier 2 investigation and Tier 3 threat hunting or advanced response. A SOC manager would be the correct choice if the question asked about governance, staffing or operational oversight roles.

  • ✗

    A dedicated threat intelligence team that provides context on indicators

    Why it's wrong here

    A dedicated threat intelligence team is an intelligence function, not a tier within the tiered SOC model. Tiered SOCs are structured around Tier 1 triage, Tier 2 investigation and Tier 3 hunting or response. Threat intelligence would be correct if the question asked which supporting capability enriches detections with indicator context.

  • ✓

    Tier 2 analysts who conduct in-depth analysis and incident response

    Why this is correct

    Tier 2 provides the escalation layer where alerts triaged by Tier 1 receive deeper investigation, correlation and containment. Without this escalation capability, incidents stall at triage, so it is essential to a tiered SOC model.

  • ✓

    Tier 1 analysts who monitor alerts and perform initial triage

    Why this is correct

    Tier 1 is the first line of defence, continuously monitoring alert queues and performing initial triage to filter false positives before escalation. This filtering function is fundamental to the tiered SOC model's division of labour.

  • ✓

    Tier 3 analysts who focus on threat hunting and advanced forensics

    Why this is correct

    Tier 3 analysts handle proactive threat hunting and deep forensic investigation, the escalation point when Tier 1 triage and Tier 2 incident response cannot resolve an incident. This satisfies the stem's requirement for a tiered SOC model, where each tier has distinct escalation responsibilities rather than duplicated monitoring duties.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.