CC · domain
Security Operations
Security Operations covers day-to-day monitoring, detection, response, and recovery. Questions present scenarios: phishing credential theft, SIEM alert triage, command-and-control traffic, and social engineering. You must pick the correct containment, analysis, or control action, and distinguish incident response steps, log sources, and access controls from distractors.
Focused practice
Practice Security Operations questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Operations
Given a scenario, identify the attack type, select the correct incident response action, and know which control or log source applies. The key is matching the response step to the situation, especially containment before eradication.
SIEM correlation of logs and alerts for detection and triage
Incident response phases: preparation, detection, containment, eradication, recovery
Disabling accounts, revoking sessions, and resetting credentials during containment
Phishing, pretexting, and social engineering recognition and reporting
Watch out for
Common Security Operations exam traps
- ▸Confusing containment with eradication: disabling a compromised account stops access, but malware or persistence still needs removal.
- ▸Treating a SIEM as a prevention tool; it aggregates and correlates logs and alerts, it does not block traffic by itself.
- ▸Assuming antivirus or a firewall alone satisfies monitoring; continuous log review and alert triage are required.
Question index
All Security Operations questions (75)
Click any question to see the full explanation, or start a practice session above.
An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?
Hard2A configuration management tool detects that a critical server's security settings have changed from the approved baseline. What is the first action the security team should take?
Hard3A security administrator is configuring a new Windows server and wants to ensure that only necessary services and ports are enabled. After installation, the administrator runs a port scan and finds that port 3389 is open. Which action should the administrator take FIRST to reduce the attack surface?
Medium4A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?
Hard5An employee receives an email from the CEO asking for an urgent wire transfer to a new vendor. The email address is slightly misspelled. What type of attack is this?
Medium6A security administrator is configuring a firewall to protect an internal network. The administrator needs to allow only HTTP and HTTPS traffic from the internal network to the internet, while blocking all other outbound traffic. Which of the following should the administrator implement?
Medium7An organization's security policy requires that all employees use unique, complex passwords for their domain accounts. A security analyst is reviewing a list of common password mistakes. Which of the following best describes a practice that undermines this policy?
Easy8A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?
Easy9An organization must retain authentication logs for compliance with PCI DSS. What is the minimum retention period and the requirement for immediate availability?
Medium10To protect the integrity of log files, which of the following is a best practice?
Easy11Which of the following is an indicator of a phishing email?
Easy12An employee receives an email that appears to be from the CEO requesting an urgent wire transfer to a new vendor. The email contains several grammatical errors and the sender's address is slightly misspelled. What type of security incident is this?
Medium13A security analyst is reviewing network flow logs and sees periodic outbound connections from an internal server to an external IP address on TCP port 443 every 30 minutes. The connections transfer small amounts of data and the external IP resolves to a newly registered domain. The server has no business need for internet access. Which type of malicious activity is most consistent with this pattern?
Hard14A security operations center receives an alert that a workstation is communicating with a known command-and-control IP address over HTTPS on port 443. The endpoint agent shows no malware signature match. Which containment action should the analyst take first to limit damage while preserving the ability to investigate?
Hard15A security analyst is reviewing endpoint logs and sees repeated entries showing that a process attempted to modify the Windows registry key HKLM\SYSTEM\CurrentControlSet\Control\Lsa and then attempted to read the SAM database file. The process is not a known administrative tool and was launched from a user's temporary folder. Which type of activity is MOST likely occurring?
Medium16An organization wants to ensure that all workstations are configured according to a hardened baseline. Which process detects when a workstation deviates from this baseline?
Medium17An employee reports that their laptop suddenly displays a message demanding payment in cryptocurrency to restore access to files, and the files now have an unfamiliar extension. The employee has not clicked any links recently. Which type of malware is MOST likely responsible?
Easy18A security analyst reviewing web server logs sees repeated requests containing strings such as '../../etc/passwd' and '..%2f..%2fwindows%2fsystem32'. The requests originate from a single external address and target a file-download endpoint. Which type of attack is most likely occurring?
Medium19An organization needs to retain authentication logs for compliance with PCI DSS. What is the minimum retention period required, and how long must the logs be immediately available?
Medium20A security operations center (SOC) is reviewing its incident response plan and wants to improve detection of data exfiltration over encrypted channels. Which TWO monitoring approaches would BEST help identify potential exfiltration in this scenario? (Choose two.)
Hard21An organization is planning to implement a security awareness program. Which TWO topics should be included to address common social engineering attacks?
Medium22An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?
Medium23A security analyst receives an alert that a user account successfully authenticated to the corporate VPN from two geographically distant countries within a five-minute window. The user is currently traveling and confirms only one login. Which conclusion is MOST appropriate for the analyst to draw at this stage?
Hard24An organization is implementing a security baseline for new servers. Which THREE components are typically included in a hardened baseline configuration? (Choose three.)
Hard25A SOC analyst detects a pattern of outbound traffic from an internal server to a known malicious IP address. Which SOC tier should this alert be escalated to for a deeper investigation?
Medium26During an incident investigation, an analyst needs to determine which user account created a specific file on a shared drive at a particular time. The organization enables auditing on the file server. Which Windows event log should the analyst review?
Medium27What is the primary purpose of a Security Information and Event Management (SIEM) system?
Easy28A SOC analyst is investigating a potential data exfiltration incident. Which TWO log sources would be most useful for identifying outbound data transfers? (Select TWO)
Medium29A security team is implementing a Security Information and Event Management (SIEM) system. Which TWO log sources are most critical for detecting unauthorized access attempts on a Linux server? (Choose two.)
Medium30A security analyst is reviewing email gateway logs and notices a message that passed authentication checks but contains a URL pointing to a look-alike domain registered three days ago. The message appears to come from the organization's CEO and requests an urgent wire transfer. Which type of attack is MOST likely being attempted?
Medium31A security team wants to detect when an attacker is using a compromised account to move laterally between servers inside the network. Which monitoring approach would best surface this activity?
Medium32A security analyst is reviewing network logs to detect potential intrusions. Which TWO of the following are examples of network-based indicators of compromise? (Choose two.)
Medium33An organization is implementing a security awareness program. Which THREE topics should be included to address common social engineering attacks? (Select THREE)
Medium34A company's SIEM solution aggregates logs from various sources and generates an alert when multiple failed logins occur within a short timeframe. Which log source is most likely to provide the data for this alert?
Medium35During an incident, a responder needs to capture the contents of volatile memory on a running Linux server before shutting it down, because encryption keys and running processes may only exist in RAM. Which action BEST preserves this volatile evidence?
Hard36During an incident, an analyst needs to determine whether a compromised account was used to access a sensitive file share. The file server runs Windows and the organization uses centralized authentication. Which log source should the analyst review first to identify the account's access to the share?
Hard37A security administrator is reviewing firewall logs and notices repeated inbound connection attempts to TCP port 3389 from multiple external IP addresses. Which type of attack is MOST likely occurring?
Medium38A security administrator is hardening a new Linux web server before it is placed into production. Which TWO practices reduce the attack surface of the operating system itself? (Choose two.)
Medium39During an incident, an analyst collects a forensic image of a compromised server's disk. The organization's policy requires preserving evidence for potential legal proceedings. Which action best maintains the integrity of the collected evidence?
Hard40A security operations center (SOC) receives an alert about a possible insider threat. An employee in the finance department has been accessing large amounts of sensitive data outside of normal working hours and emailing it to a personal external email address. The SOC manager asks the analyst to preserve evidence for a potential legal case. Which of the following should the analyst do FIRST to ensure the evidence is admissible?
Hard41A company is building an incident response capability and wants to ensure the containment phase is effective. Which TWO activities are appropriate during containment? (Choose two.)
Medium42A security administrator is configuring a Linux web server and wants to ensure that only encrypted administrative sessions are allowed, while also preventing direct root logins over the network. Which of the following should the administrator implement?
Medium43A security administrator is configuring a firewall rule to allow only HTTP and HTTPS traffic from the internal network to the internet. Which port numbers should be permitted?
Easy44A critical zero-day vulnerability is actively being exploited in the wild, affecting an organization's internet-facing application. Which patching approach should be taken?
Medium45An organization wants to ensure that only authorized devices can connect to its corporate Wi-Fi network. The security team decides to implement a solution that requires devices to authenticate before being granted network access. Which technology should they use?
Easy46An attacker used stolen credentials from a phishing campaign to authenticate to a cloud email account. The organization's incident response team wants to immediately stop the attacker from continuing to access the mailbox while preserving evidence for investigation. Which action best meets both goals?
Medium47Which of the following is the most effective way to prevent tailgating in a secured facility?
Medium48An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?
Easy49A security analyst is reviewing access logs and notices that a former employee's account was used to access a sensitive file share three days after the employee's termination. The account should have been disabled on the termination date. Which of the following is the MOST likely explanation for this security gap?
Medium50What is the primary purpose of using security baselines derived from CIS Benchmarks?
Medium51A security analyst is reviewing logs from a Linux web server and notices the following entries: multiple failed SSH login attempts for user 'root' from various IP addresses, followed by a successful login from an IP address in a different country. Shortly after, a new user account 'backup' is created and added to the sudoers file. Which type of attack is MOST likely represented?
Hard52A company wants to reduce the risk of malware spreading from employee workstations to critical servers. The security team proposes placing firewalls between network segments and restricting traffic to only required ports and protocols. Which security control category does this approach primarily represent?
Medium53A junior administrator at a healthcare company receives a call from someone claiming to be from the IT help desk. The caller says there is a critical server issue and asks the administrator to read back the six-digit code just sent to their phone. The administrator has not requested any password reset or MFA challenge. Which social engineering principle is the caller most likely exploiting?
Easy54A security operations center receives an alert that a workstation is communicating with a known command-and-control (C2) IP address every 60 seconds at consistent intervals. The endpoint detection and response (EDR) agent has not flagged any malicious files on the host. Which type of malware behavior BEST describes this activity?
Medium55An organization implements a security baseline using CIS Benchmarks for all new servers. After a routine scan, a server is found to have a configuration that deviates from the baseline. The deviation was introduced by a system administrator to resolve a performance issue. What is the best course of action?
Hard56Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?
Easy57A security operations center (SOC) analyst is reviewing network traffic logs and notices a series of connections to an unfamiliar external IP address on port 443. The analyst suspects a command-and-control (C2) channel. Which TWO characteristics would most likely indicate that this traffic is malicious C2 activity? (Choose two.)
Hard58Which of the following is a key function of a Security Information and Event Management (SIEM) system?
Easy59A security awareness trainer is developing material on USB drop attacks. Which TWO messages should be included in the training? (Choose two.)
Medium60A security engineer is designing a patch management process. Which TWO steps are part of the standard patch lifecycle? (Select TWO)
Hard61A security administrator must configure a system so that users prove their identity with something they have plus something they know, without deploying smart cards or hardware tokens. Which authentication approach best meets this requirement?
Hard62An employee receives an email that appears to be from the IT department asking them to click a link and verify their password because of a mailbox upgrade. The link points to a domain that is misspelled but closely resembles the company's real domain. The employee reports it to the security team. What type of attack is this?
Easy63A security operations center wants to improve detection of malicious activity on endpoints. Which TWO data sources provide the most direct endpoint-level evidence for identifying suspicious process execution? (Choose two.)
Medium64Which TWO of the following are common indicators of a phishing email?
Easy65A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?
Medium66An organization is building a log management capability so its security team can detect and investigate incidents across many systems. Which TWO practices BEST support effective centralized log collection and analysis? (Choose two.)
Medium67A new employee reports receiving an email that appears to come from the CEO, urgently requesting gift card purchases for a client. The email domain looks almost identical to the company's domain but uses a different top-level domain. Which type of social engineering attack is this?
Easy68A security analyst is reviewing firewall logs and notices an unusually high number of blocked outbound connections to a single external IP address. Which TWO actions should the analyst take to investigate this potential security incident? (Choose two.)
Medium69A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?
Hard70A security analyst needs to ensure that log data cannot be altered after it is written. Which of the following is the most effective method to protect log integrity?
Hard71A security administrator discovers that a former employee's user account still exists and remains enabled three weeks after their termination. The account has valid credentials and no recent logins. Which access control principle has been violated?
Medium72After a security incident, an investigator needs to analyze logs to determine the timeline of events. Which TWO types of logs are most likely to provide evidence of lateral movement within the network?
Hard73An employee receives a call from someone claiming to be from the IT help desk. The caller says there is a problem with the employee's email and asks for the employee's password to fix it. The employee refuses and reports the call. Which social engineering technique was attempted?
Easy74A security administrator receives an alert that a user's laptop has been infected with ransomware. The user reports that all files on the laptop are encrypted and a ransom note is displayed. The administrator immediately disconnects the laptop from the network. Which of the following should be the NEXT step in the incident response process?
Medium75An organization wants to ensure that only authorized software can execute on its endpoints. A security administrator is evaluating application control methods. Which of the following is the BEST approach to meet this requirement?
EasyOther domains
All CC exam domains
Frequently asked questions
- What does the Security Operations domain cover on the CC exam?
- Given a scenario, identify the attack type, select the correct incident response action, and know which control or log source applies. The key is matching the response step to the situation, especially containment before eradication.
- How many questions are in this domain?
- This page lists all 75 Security Operations questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Operations questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.