Courseiva
Security Operations →mediumMultiple Choice

CISSP Security Operations Practice Question

A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?

⚠ Common exam trap

CISSP often tests SOC tier responsibilities — candidates assume Tier 2 handles all investigations, but deep forensics (DPI, memory analysis) is explicitly Tier 3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tier 3

Tier 3 performs advanced analysis, which explicitly includes deep packet inspection (DPI) and memory forensics. Confirming DNS tunneling exfiltration requires inspecting DNS query payloads for encoded data and analyzing process memory for injected malware — skills and tooling reserved for Tier 3. Tier 1 and Tier 2 handle triage and investigation but not advanced forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Incident manager

    Why it's wrong here

    The incident manager's primary responsibility is the overall coordination and strategic oversight of an incident, ensuring effective communication, resource allocation, and adherence to response plans. Their role is managerial and logistical, focusing on bringing an incident to resolution, rather than performing the hands-on technical analysis or deep digital forensics required to extract evidence from compromised systems. They direct the forensic efforts but do not execute them.

  • ✗

    Tier 2

    Why it's wrong here

    Tier 2 analysts are responsible for in-depth investigation of escalated alerts, correlating events, and executing containment and eradication procedures. While they possess strong analytical skills for incident response, their expertise typically does not extend to the highly specialized techniques of deep digital forensics, such as advanced memory analysis, file system reconstruction, or malware reverse engineering. These specialized forensic tasks often require dedicated tools and certifications beyond the scope of a typical Tier 2 role.

  • ✗

    Tier 1

    Why it's wrong here

    Tier 1 analysts serve as the first line of defense, primarily focused on monitoring security tools, validating alerts, and performing initial triage according to predefined playbooks. Their role is to quickly identify potential incidents and escalate them appropriately, lacking the necessary training, specialized tools, or authorization to conduct any form of detailed investigation or digital forensic analysis. They are not equipped for deep technical analysis.

  • ✓

    Tier 3

    Why this is correct

    Tier 3 analysts, often comprising threat hunters, malware reverse engineers, and digital forensics experts, possess the most advanced technical skills within a SOC. They are uniquely equipped to conduct deep-dive forensic examinations, including advanced memory forensics, file system analysis, and complex artifact reconstruction, utilizing specialized tools and methodologies. This tier is essential for uncovering sophisticated attack techniques, attributing threats, and developing proactive defenses based on expert-level forensic insights.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.