Courseiva

CC · domain

Security Operations

Security Operations covers day-to-day monitoring, detection, response, and recovery. Questions present scenarios: phishing credential theft, SIEM alert triage, command-and-control traffic, and social engineering. You must pick the correct containment, analysis, or control action, and distinguish incident response steps, log sources, and access controls from distractors.

75 questions17 easy38 medium20 hard

Focused practice

Practice Security Operations questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Operations

Given a scenario, identify the attack type, select the correct incident response action, and know which control or log source applies. The key is matching the response step to the situation, especially containment before eradication.

SIEM correlation of logs and alerts for detection and triage

Incident response phases: preparation, detection, containment, eradication, recovery

Disabling accounts, revoking sessions, and resetting credentials during containment

Phishing, pretexting, and social engineering recognition and reporting

Watch out for

Common Security Operations exam traps

  • ▸Confusing containment with eradication: disabling a compromised account stops access, but malware or persistence still needs removal.
  • ▸Treating a SIEM as a prevention tool; it aggregates and correlates logs and alerts, it does not block traffic by itself.
  • ▸Assuming antivirus or a firewall alone satisfies monitoring; continuous log review and alert triage are required.

Question index

All Security Operations questions (75)

Click any question to see the full explanation, or start a practice session above.

1

An organization has a legacy system that cannot be patched due to vendor end-of-life. The system is critical for operations. Which compensating control is most appropriate to reduce the risk of exploitation?

Hard
2

A configuration management tool detects that a critical server's security settings have changed from the approved baseline. What is the first action the security team should take?

Hard
3

A security administrator is configuring a new Windows server and wants to ensure that only necessary services and ports are enabled. After installation, the administrator runs a port scan and finds that port 3389 is open. Which action should the administrator take FIRST to reduce the attack surface?

Medium
4

A SOC analyst reviews a SIEM alert indicating a high volume of outbound traffic from a server to an external IP address known for command-and-control activity. The analyst has confirmed the alert is not a false positive. What is the most appropriate next step?

Hard
5

An employee receives an email from the CEO asking for an urgent wire transfer to a new vendor. The email address is slightly misspelled. What type of attack is this?

Medium
6

A security administrator is configuring a firewall to protect an internal network. The administrator needs to allow only HTTP and HTTPS traffic from the internal network to the internet, while blocking all other outbound traffic. Which of the following should the administrator implement?

Medium
7

An organization's security policy requires that all employees use unique, complex passwords for their domain accounts. A security analyst is reviewing a list of common password mistakes. Which of the following best describes a practice that undermines this policy?

Easy
8

A security analyst at a Security Operations Centre (SOC) receives an alert from the SIEM indicating multiple failed login attempts for a user account followed by a successful login from an unusual geographic location. According to SOC tier responsibilities, which tier should perform the initial triage of this alert?

Easy
9

An organization must retain authentication logs for compliance with PCI DSS. What is the minimum retention period and the requirement for immediate availability?

Medium
10

To protect the integrity of log files, which of the following is a best practice?

Easy
11

Which of the following is an indicator of a phishing email?

Easy
12

An employee receives an email that appears to be from the CEO requesting an urgent wire transfer to a new vendor. The email contains several grammatical errors and the sender's address is slightly misspelled. What type of security incident is this?

Medium
13

A security analyst is reviewing network flow logs and sees periodic outbound connections from an internal server to an external IP address on TCP port 443 every 30 minutes. The connections transfer small amounts of data and the external IP resolves to a newly registered domain. The server has no business need for internet access. Which type of malicious activity is most consistent with this pattern?

Hard
14

A security operations center receives an alert that a workstation is communicating with a known command-and-control IP address over HTTPS on port 443. The endpoint agent shows no malware signature match. Which containment action should the analyst take first to limit damage while preserving the ability to investigate?

Hard
15

A security analyst is reviewing endpoint logs and sees repeated entries showing that a process attempted to modify the Windows registry key HKLM\SYSTEM\CurrentControlSet\Control\Lsa and then attempted to read the SAM database file. The process is not a known administrative tool and was launched from a user's temporary folder. Which type of activity is MOST likely occurring?

Medium
16

An organization wants to ensure that all workstations are configured according to a hardened baseline. Which process detects when a workstation deviates from this baseline?

Medium
17

An employee reports that their laptop suddenly displays a message demanding payment in cryptocurrency to restore access to files, and the files now have an unfamiliar extension. The employee has not clicked any links recently. Which type of malware is MOST likely responsible?

Easy
18

A security analyst reviewing web server logs sees repeated requests containing strings such as '../../etc/passwd' and '..%2f..%2fwindows%2fsystem32'. The requests originate from a single external address and target a file-download endpoint. Which type of attack is most likely occurring?

Medium
19

An organization needs to retain authentication logs for compliance with PCI DSS. What is the minimum retention period required, and how long must the logs be immediately available?

Medium
20

A security operations center (SOC) is reviewing its incident response plan and wants to improve detection of data exfiltration over encrypted channels. Which TWO monitoring approaches would BEST help identify potential exfiltration in this scenario? (Choose two.)

Hard
21

An organization is planning to implement a security awareness program. Which TWO topics should be included to address common social engineering attacks?

Medium
22

An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?

Medium
23

A security analyst receives an alert that a user account successfully authenticated to the corporate VPN from two geographically distant countries within a five-minute window. The user is currently traveling and confirms only one login. Which conclusion is MOST appropriate for the analyst to draw at this stage?

Hard
24

An organization is implementing a security baseline for new servers. Which THREE components are typically included in a hardened baseline configuration? (Choose three.)

Hard
25

A SOC analyst detects a pattern of outbound traffic from an internal server to a known malicious IP address. Which SOC tier should this alert be escalated to for a deeper investigation?

Medium
26

During an incident investigation, an analyst needs to determine which user account created a specific file on a shared drive at a particular time. The organization enables auditing on the file server. Which Windows event log should the analyst review?

Medium
27

What is the primary purpose of a Security Information and Event Management (SIEM) system?

Easy
28

A SOC analyst is investigating a potential data exfiltration incident. Which TWO log sources would be most useful for identifying outbound data transfers? (Select TWO)

Medium
29

A security team is implementing a Security Information and Event Management (SIEM) system. Which TWO log sources are most critical for detecting unauthorized access attempts on a Linux server? (Choose two.)

Medium
30

A security analyst is reviewing email gateway logs and notices a message that passed authentication checks but contains a URL pointing to a look-alike domain registered three days ago. The message appears to come from the organization's CEO and requests an urgent wire transfer. Which type of attack is MOST likely being attempted?

Medium
31

A security team wants to detect when an attacker is using a compromised account to move laterally between servers inside the network. Which monitoring approach would best surface this activity?

Medium
32

A security analyst is reviewing network logs to detect potential intrusions. Which TWO of the following are examples of network-based indicators of compromise? (Choose two.)

Medium
33

An organization is implementing a security awareness program. Which THREE topics should be included to address common social engineering attacks? (Select THREE)

Medium
34

A company's SIEM solution aggregates logs from various sources and generates an alert when multiple failed logins occur within a short timeframe. Which log source is most likely to provide the data for this alert?

Medium
35

During an incident, a responder needs to capture the contents of volatile memory on a running Linux server before shutting it down, because encryption keys and running processes may only exist in RAM. Which action BEST preserves this volatile evidence?

Hard
36

During an incident, an analyst needs to determine whether a compromised account was used to access a sensitive file share. The file server runs Windows and the organization uses centralized authentication. Which log source should the analyst review first to identify the account's access to the share?

Hard
37

A security administrator is reviewing firewall logs and notices repeated inbound connection attempts to TCP port 3389 from multiple external IP addresses. Which type of attack is MOST likely occurring?

Medium
38

A security administrator is hardening a new Linux web server before it is placed into production. Which TWO practices reduce the attack surface of the operating system itself? (Choose two.)

Medium
39

During an incident, an analyst collects a forensic image of a compromised server's disk. The organization's policy requires preserving evidence for potential legal proceedings. Which action best maintains the integrity of the collected evidence?

Hard
40

A security operations center (SOC) receives an alert about a possible insider threat. An employee in the finance department has been accessing large amounts of sensitive data outside of normal working hours and emailing it to a personal external email address. The SOC manager asks the analyst to preserve evidence for a potential legal case. Which of the following should the analyst do FIRST to ensure the evidence is admissible?

Hard
41

A company is building an incident response capability and wants to ensure the containment phase is effective. Which TWO activities are appropriate during containment? (Choose two.)

Medium
42

A security administrator is configuring a Linux web server and wants to ensure that only encrypted administrative sessions are allowed, while also preventing direct root logins over the network. Which of the following should the administrator implement?

Medium
43

A security administrator is configuring a firewall rule to allow only HTTP and HTTPS traffic from the internal network to the internet. Which port numbers should be permitted?

Easy
44

A critical zero-day vulnerability is actively being exploited in the wild, affecting an organization's internet-facing application. Which patching approach should be taken?

Medium
45

An organization wants to ensure that only authorized devices can connect to its corporate Wi-Fi network. The security team decides to implement a solution that requires devices to authenticate before being granted network access. Which technology should they use?

Easy
46

An attacker used stolen credentials from a phishing campaign to authenticate to a cloud email account. The organization's incident response team wants to immediately stop the attacker from continuing to access the mailbox while preserving evidence for investigation. Which action best meets both goals?

Medium
47

Which of the following is the most effective way to prevent tailgating in a secured facility?

Medium
48

An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?

Easy
49

A security analyst is reviewing access logs and notices that a former employee's account was used to access a sensitive file share three days after the employee's termination. The account should have been disabled on the termination date. Which of the following is the MOST likely explanation for this security gap?

Medium
50

What is the primary purpose of using security baselines derived from CIS Benchmarks?

Medium
51

A security analyst is reviewing logs from a Linux web server and notices the following entries: multiple failed SSH login attempts for user 'root' from various IP addresses, followed by a successful login from an IP address in a different country. Shortly after, a new user account 'backup' is created and added to the sudoers file. Which type of attack is MOST likely represented?

Hard
52

A company wants to reduce the risk of malware spreading from employee workstations to critical servers. The security team proposes placing firewalls between network segments and restricting traffic to only required ports and protocols. Which security control category does this approach primarily represent?

Medium
53

A junior administrator at a healthcare company receives a call from someone claiming to be from the IT help desk. The caller says there is a critical server issue and asks the administrator to read back the six-digit code just sent to their phone. The administrator has not requested any password reset or MFA challenge. Which social engineering principle is the caller most likely exploiting?

Easy
54

A security operations center receives an alert that a workstation is communicating with a known command-and-control (C2) IP address every 60 seconds at consistent intervals. The endpoint detection and response (EDR) agent has not flagged any malicious files on the host. Which type of malware behavior BEST describes this activity?

Medium
55

An organization implements a security baseline using CIS Benchmarks for all new servers. After a routine scan, a server is found to have a configuration that deviates from the baseline. The deviation was introduced by a system administrator to resolve a performance issue. What is the best course of action?

Hard
56

Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?

Easy
57

A security operations center (SOC) analyst is reviewing network traffic logs and notices a series of connections to an unfamiliar external IP address on port 443. The analyst suspects a command-and-control (C2) channel. Which TWO characteristics would most likely indicate that this traffic is malicious C2 activity? (Choose two.)

Hard
58

Which of the following is a key function of a Security Information and Event Management (SIEM) system?

Easy
59

A security awareness trainer is developing material on USB drop attacks. Which TWO messages should be included in the training? (Choose two.)

Medium
60

A security engineer is designing a patch management process. Which TWO steps are part of the standard patch lifecycle? (Select TWO)

Hard
61

A security administrator must configure a system so that users prove their identity with something they have plus something they know, without deploying smart cards or hardware tokens. Which authentication approach best meets this requirement?

Hard
62

An employee receives an email that appears to be from the IT department asking them to click a link and verify their password because of a mailbox upgrade. The link points to a domain that is misspelled but closely resembles the company's real domain. The employee reports it to the security team. What type of attack is this?

Easy
63

A security operations center wants to improve detection of malicious activity on endpoints. Which TWO data sources provide the most direct endpoint-level evidence for identifying suspicious process execution? (Choose two.)

Medium
64

Which TWO of the following are common indicators of a phishing email?

Easy
65

A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?

Medium
66

An organization is building a log management capability so its security team can detect and investigate incidents across many systems. Which TWO practices BEST support effective centralized log collection and analysis? (Choose two.)

Medium
67

A new employee reports receiving an email that appears to come from the CEO, urgently requesting gift card purchases for a client. The email domain looks almost identical to the company's domain but uses a different top-level domain. Which type of social engineering attack is this?

Easy
68

A security analyst is reviewing firewall logs and notices an unusually high number of blocked outbound connections to a single external IP address. Which TWO actions should the analyst take to investigate this potential security incident? (Choose two.)

Medium
69

A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?

Hard
70

A security analyst needs to ensure that log data cannot be altered after it is written. Which of the following is the most effective method to protect log integrity?

Hard
71

A security administrator discovers that a former employee's user account still exists and remains enabled three weeks after their termination. The account has valid credentials and no recent logins. Which access control principle has been violated?

Medium
72

After a security incident, an investigator needs to analyze logs to determine the timeline of events. Which TWO types of logs are most likely to provide evidence of lateral movement within the network?

Hard
73

An employee receives a call from someone claiming to be from the IT help desk. The caller says there is a problem with the employee's email and asks for the employee's password to fix it. The employee refuses and reports the call. Which social engineering technique was attempted?

Easy
74

A security administrator receives an alert that a user's laptop has been infected with ransomware. The user reports that all files on the laptop are encrypted and a ransom note is displayed. The administrator immediately disconnects the laptop from the network. Which of the following should be the NEXT step in the incident response process?

Medium
75

An organization wants to ensure that only authorized software can execute on its endpoints. A security administrator is evaluating application control methods. Which of the following is the BEST approach to meet this requirement?

Easy

Frequently asked questions

What does the Security Operations domain cover on the CC exam?
Given a scenario, identify the attack type, select the correct incident response action, and know which control or log source applies. The key is matching the response step to the situation, especially containment before eradication.
How many questions are in this domain?
This page lists all 75 Security Operations questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Operations questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cc ISC2-CC cc security operations Practice Questions