CISSP Security Operations Practice Question
A SOC analyst at Tier 1 identifies a potential malware infection on a user workstation. What is the next step in the standard incident response process?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the incident to Tier 2 analyst for further investigation
Tier 1 analysts typically triage alerts and escalate if they cannot resolve them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the SIEM correlation rule to ignore similar alerts
Why it's wrong here
Updating SIEM correlation rules to ignore alerts is an inappropriate and potentially dangerous response to a *potential* malware infection. This action would prevent future detection of similar threats, effectively masking a security issue rather than addressing it. Rule tuning is a post-incident activity or part of routine SIEM management, performed after thorough investigation and confirmation that alerts are false positives, not an initial step when a legitimate threat is suspected.
- ✓
Escalate the incident to Tier 2 analyst for further investigation
Why this is correct
Escalating the incident to a Tier 2 analyst for further investigation is the correct and standard procedure for a Tier 1 SOC analyst who has identified a potential malware infection. Tier 1 analysts are primarily responsible for initial alert triage, basic investigation, and confirming the legitimacy of an alert. If the incident requires more advanced analysis, specialized tools, or decision-making beyond their scope, proper escalation ensures the incident is handled by personnel with the appropriate expertise and authority, following established incident response playbooks.
- ✗
Disconnect the workstation from the network immediately
Why it's wrong here
Immediately disconnecting the workstation from the network is a premature containment action that a Tier 1 analyst should not undertake without further analysis and approval. While containment is crucial, an uncoordinated disconnection can disrupt business operations, potentially destroy volatile memory evidence, and prevent further network-based monitoring or analysis by higher-tier analysts. The decision for such a drastic measure typically rests with Tier 2 or incident response leads, who can assess the full impact and determine the most effective containment strategy.
- ✗
Perform a deep forensic analysis of the workstation
Why it's wrong here
Performing a deep forensic analysis of the workstation is a specialized and time-consuming task that falls outside the typical responsibilities and skill set of a Tier 1 SOC analyst. Their role is focused on initial detection and triage, not in-depth evidence collection and analysis. Deep forensics requires advanced tools and expertise, usually conducted by Tier 3 analysts, dedicated forensic specialists, or incident responders, and typically occurs after an incident has been confirmed, contained, and a formal investigation initiated.
Visual reference
Go deeper
Related to this question
Learn chapter
Incident Response and Business Continuity
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.