CC · domain
Security Operations
Practise ISC2 Certified in Cybersecurity CC Security Operations practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Security Operations questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Operations
Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Security Operations exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Security Operations questions (45)
Click any question to see the full explanation, or start a practice session above.
An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?
Hard2A configuration management tool detects that a critical server's security settings have changed from the approved baseline. What is the first action the security team should take?
Hard3A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?
Hard4An employee receives an email from the CEO asking for an urgent wire transfer to a new vendor. The email address is slightly misspelled. What type of attack is this?
Medium5A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?
Easy6An organization must retain authentication logs for compliance with PCI DSS. What is the minimum retention period and the requirement for immediate availability?
Medium7To protect the integrity of log files, which of the following is a best practice?
Easy8Which of the following is an indicator of a phishing email?
Easy9An employee receives an email that appears to be from the CEO requesting an urgent wire transfer to a new vendor. The email contains several grammatical errors and the sender's address is slightly misspelled. What type of security incident is this?
Medium10An organization is implementing a patch management policy. Which THREE steps are part of the standard patch lifecycle?
Medium11An organization wants to ensure that all workstations are configured according to a hardened baseline. Which process detects when a workstation deviates from this baseline?
Medium12An organization needs to retain authentication logs for compliance with PCI DSS. What is the minimum retention period required, and how long must the logs be immediately available?
Medium13An organization is planning to implement a security awareness program. Which TWO topics should be included to address common social engineering attacks?
Medium14An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?
Medium15A legacy system cannot be patched due to vendor unavailability. Which compensating control would be most effective in reducing the risk of exploitation?
Hard16A company discovers a critical vulnerability in a widely used software application. The vendor has released a patch, but the company's patch management policy requires testing before deployment. What is the best course of action?
Medium17An organization is implementing a security baseline for new servers. Which THREE components are typically included in a hardened baseline configuration? (Choose three.)
Hard18A SOC analyst detects a pattern of outbound traffic from an internal server to a known malicious IP address. Which SOC tier should this alert be escalated to for a deeper investigation?
Medium19What is the primary purpose of a Security Information and Event Management (SIEM) system?
Easy20A critical vulnerability is discovered in a widely used VPN appliance that is actively being exploited in the wild. The vendor has released an emergency patch. However, the organization's patch management policy requires testing in a staging environment before production deployment. What should the security team do?
Hard21A SOC analyst is investigating a potential data exfiltration incident. Which TWO log sources would be most useful for identifying outbound data transfers? (Select TWO)
Medium22A Security Operations Center (SOC) Tier 1 analyst notices an alert for a failed login attempt from an unusual geographic location. What is the primary responsibility of a Tier 1 analyst in this scenario?
Easy23An organization is implementing a security awareness program. Which THREE topics should be included to address common social engineering attacks? (Select THREE)
Medium24A company's SIEM solution aggregates logs from various sources and generates an alert when multiple failed logins occur within a short timeframe. Which log source is most likely to provide the data for this alert?
Medium25A SOC analyst notices a large spike in outbound traffic from a workstation that is not scheduled for any data transfers. Upon checking the SIEM, the analyst sees that the workstation's antivirus was disabled 30 minutes ago. What type of logs should the analyst examine first to understand the sequence of events?
Medium26Which of the following is an indicator of a phishing email?
Easy27During a patch management cycle, a new vulnerability is disclosed in a widely used web server software. What is the first step an organization should take in the patch lifecycle?
Easy28A critical zero-day vulnerability is actively being exploited in the wild, affecting an organization's internet-facing application. Which patching approach should be taken?
Medium29Which of the following is the most effective way to prevent tailgating in a secured facility?
Medium30An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?
Easy31What is the primary purpose of using security baselines derived from CIS Benchmarks?
Medium32An organization implements a security baseline using CIS Benchmarks for all new servers. After a routine scan, a server is found to have a configuration that deviates from the baseline. The deviation was introduced by a system administrator to resolve a performance issue. What is the best course of action?
Hard33Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?
Easy34A SOC team is reviewing security controls for a new critical application. Which THREE of the following are essential components of a security operations capability?
Medium35Which of the following is a key function of a Security Information and Event Management (SIEM) system?
Easy36An organization has a legacy system that cannot be patched due to vendor end-of-life. Which compensating control is most effective at reducing the risk of exploitation via network-based attacks?
Hard37A security awareness trainer is developing material on USB drop attacks. Which TWO messages should be included in the training? (Choose two.)
Medium38A security engineer is designing a patch management process. Which TWO steps are part of the standard patch lifecycle? (Select TWO)
Hard39Which TWO of the following are common indicators of a phishing email?
Easy40A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?
Medium41A security analyst is reviewing firewall logs and notices an unusually high number of blocked outbound connections to a single external IP address. Which TWO actions should the analyst take to investigate this potential security incident? (Choose two.)
Medium42A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?
Hard43A security analyst needs to ensure that log data cannot be altered after it is written. Which of the following is the most effective method to protect log integrity?
Hard44Which type of log should be monitored to detect a user account that has been granted administrative privileges unexpectedly?
Medium45After a security incident, an investigator needs to analyze logs to determine the timeline of events. Which TWO types of logs are most likely to provide evidence of lateral movement within the network?
HardOther domains
All CC exam domains
Frequently asked questions
- What does the Security Operations domain cover on the CC exam?
- Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 45 Security Operations questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Operations questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.