Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

CISSP Security Operations Practice Question

A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Tier 3

Tier 3 handles advanced analysis including memory forensics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Incident manager

    Why it's wrong here

    The incident manager's primary responsibility is the overall coordination and strategic oversight of an incident, ensuring effective communication, resource allocation, and adherence to response plans. Their role is managerial and logistical, focusing on bringing an incident to resolution, rather than performing the hands-on technical analysis or deep digital forensics required to extract evidence from compromised systems. They direct the forensic efforts but do not execute them.

  • Tier 2

    Why it's wrong here

    Tier 2 analysts are responsible for in-depth investigation of escalated alerts, correlating events, and executing containment and eradication procedures. While they possess strong analytical skills for incident response, their expertise typically does not extend to the highly specialized techniques of deep digital forensics, such as advanced memory analysis, file system reconstruction, or malware reverse engineering. These specialized forensic tasks often require dedicated tools and certifications beyond the scope of a typical Tier 2 role.

  • Tier 1

    Why it's wrong here

    Tier 1 analysts serve as the first line of defense, primarily focused on monitoring security tools, validating alerts, and performing initial triage according to predefined playbooks. Their role is to quickly identify potential incidents and escalate them appropriately, lacking the necessary training, specialized tools, or authorization to conduct any form of detailed investigation or digital forensic analysis. They are not equipped for deep technical analysis.

  • Tier 3

    Why this is correct

    Tier 3 analysts, often comprising threat hunters, malware reverse engineers, and digital forensics experts, possess the most advanced technical skills within a SOC. They are uniquely equipped to conduct deep-dive forensic examinations, including advanced memory forensics, file system analysis, and complex artifact reconstruction, utilizing specialized tools and methodologies. This tier is essential for uncovering sophisticated attack techniques, attributing threats, and developing proactive defenses based on expert-level forensic insights.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.