Courseiva

CC · topic practice

Security Operations practice questions

Security Operations covers day-to-day monitoring, detection, response, and recovery. Questions present scenarios: phishing credential theft, SIEM alert triage, command-and-control traffic, and social engineering. You must pick the correct containment, analysis, or control action, and distinguish incident response steps, log sources, and access controls from distractors.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Operations

What the exam tests

What to know about Security Operations

Given a scenario, identify the attack type, select the correct incident response action, and know which control or log source applies. The key is matching the response step to the situation, especially containment before eradication.

SIEM correlation of logs and alerts for detection and triage

Incident response phases: preparation, detection, containment, eradication, recovery

Disabling accounts, revoking sessions, and resetting credentials during containment

Phishing, pretexting, and social engineering recognition and reporting

Watch out for

Common Security Operations exam traps

  • ▸Confusing containment with eradication: disabling a compromised account stops access, but malware or persistence still needs removal.
  • ▸Treating a SIEM as a prevention tool; it aggregates and correlates logs and alerts, it does not block traffic by itself.
  • ▸Assuming antivirus or a firewall alone satisfies monitoring; continuous log review and alert triage are required.

Practice set

Security Operations questions

20 questions · select your answer, then reveal the explanation

A company discovers a critical vulnerability in a widely used software application. The vendor has released a patch, but the company's patch management policy requires testing before deployment. What is the best course of action?

An organization has a legacy system that cannot be patched due to vendor end-of-life. Which compensating control is most effective at reducing the risk of exploitation via network-based attacks?

A Security Operations Center (SOC) Tier 1 analyst notices an alert for a failed login attempt from an unusual geographic location. What is the primary responsibility of a Tier 1 analyst in this scenario?

During a patch management cycle, a new vulnerability is disclosed in a widely used web server software. What is the first step an organization should take in the patch lifecycle?

A legacy system cannot be patched due to vendor unavailability. Which compensating control would be most effective in reducing the risk of exploitation?

Which of the following is an indicator of a phishing email?

Question 7hardmultiple choice
Read the full VPN explanation →

A critical vulnerability is discovered in a widely used VPN appliance that is actively being exploited in the wild. The vendor has released an emergency patch. However, the organization's patch management policy requires testing in a staging environment before production deployment. What should the security team do?

A SOC analyst notices a large spike in outbound traffic from a workstation that is not scheduled for any data transfers. Upon checking the SIEM, the analyst sees that the workstation's antivirus was disabled 30 minutes ago. What type of logs should the analyst examine first to understand the sequence of events?

Which type of log should be monitored to detect a user account that has been granted administrative privileges unexpectedly?

A SOC team is reviewing security controls for a new critical application. Which THREE of the following are essential components of a security operations capability?

An organization is implementing a patch management policy. Which THREE steps are part of the standard patch lifecycle?

A small company's file server was encrypted by ransomware overnight, and no offline backups exist. The IT manager asks which security principle was most directly violated by relying only on a single, always-connected backup target.

A security analyst is investigating a suspected insider threat. The employee has access to sensitive files and is suspected of copying data to a personal USB drive. Which Windows event log would BEST provide evidence of this activity?

A security administrator is configuring a Windows file server that stores payroll records. The requirement is that only members of the Payroll group can read the files, while members of the HR group must be able to modify them, and everyone else must be denied access. Which access control model best fits this requirement?

Question 15mediummulti select
Read the full Ansible explanation →

A security operations team is building a playbook for handling a suspected malware outbreak on a user's workstation. Which TWO actions should be performed during the containment phase? (Choose two.)

Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?

A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?

An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?

A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?

Which of the following is an indicator of a phishing email?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Operations sessions

Start a Security Operations only practice session

Every question in these sessions is drawn from the Security Operations domain — nothing else.

Related practice questions

Related CC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CC exam test about Security Operations?
Given a scenario, identify the attack type, select the correct incident response action, and know which control or log source applies. The key is matching the response step to the situation, especially containment before eradication.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Operations questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Operations domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CC topics?
Use the topic links above to move to related areas, or go back to the CC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CC exam covers. They are not copied from any real exam or dump site.