Courseiva
Security Operations →mediumMultiple Select

CISSP Security Operations Practice Question

An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)

⚠ Common exam trap

CISSP often tests the boundaries between SOC tiers, so candidates assign advanced tasks like threat hunting or detection engineering to Tier 1 when those belong to Tier 2 or Tier 3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Monitoring SIEM alerts and performing initial triage

Option B is correct because Tier 1 analysts are the first line of defense in a SOC, continuously monitoring SIEM alerts and performing initial triage to determine whether an alert is a true positive, false positive, or benign event. Option C is correct because a core Tier 1 responsibility is escalating validated or suspicious incidents to Tier 2 for deeper investigation when the alert exceeds their scope or requires advanced analysis. Threat hunting (A) is typically performed by Tier 2 or Tier 3 analysts who proactively search for hidden threats rather than react to alerts. In-depth forensic analysis (D) is a Tier 3 or dedicated incident response function requiring specialized tools and expertise. Developing new detection rules for the SIEM (E) is usually the responsibility of Tier 2/Tier 3 analysts or detection engineers, not Tier 1.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Performing threat hunting

    Why it's wrong here

    Threat hunting is a proactive security discipline focused on seeking out unknown threats that have evaded existing security controls. This advanced activity requires specialized skills in data analysis, hypothesis generation, and deep understanding of adversary tactics, techniques, and procedures (TTPs), making it a responsibility for more experienced Tier 2 or Tier 3 analysts, not the initial reactive duties of Tier 1.

  • ✓

    Monitoring SIEM alerts and performing initial triage

    Why this is correct

    Tier 1 SOC analysts are primarily responsible for the continuous monitoring of security information and event management (SIEM) systems. Their core duty involves reviewing incoming alerts, correlating events, and performing an initial assessment to determine if an alert represents a legitimate security incident. This initial triage ensures that potential threats are identified promptly and categorized for appropriate next steps.

  • ✓

    Escalating incidents to Tier 2 when necessary

    Why this is correct

    A critical function of Tier 1 analysts is to recognize when an incident exceeds their defined scope of resolution or requires more in-depth investigation. When an alert is validated as a true positive and cannot be resolved using standard operating procedures or requires specialized expertise, Tier 1 personnel are responsible for accurately documenting and escalating the incident to Tier 2. This ensures that complex or critical incidents receive the necessary advanced attention without delay.

  • ✗

    Conducting in-depth forensic analysis

    Why it's wrong here

    In-depth forensic analysis involves meticulously examining digital evidence from compromised systems, networks, or applications to reconstruct events, identify root causes, and gather intelligence for legal or remediation purposes. This highly specialized task requires advanced expertise in forensic tools, operating system internals, memory analysis, and legal chain-of-custody procedures. Such complex investigations are typically reserved for highly skilled Tier 3 incident responders or dedicated forensic specialists, far beyond the initial response capabilities of Tier 1.

  • ✗

    Developing new detection rules for the SIEM

    Why it's wrong here

    The creation and refinement of new detection rules for a SIEM system involve a deep understanding of log sources, threat intelligence, attack patterns, and the specific query language of the SIEM platform. This proactive engineering task requires analytical skills to identify gaps in current detection capabilities and the technical expertise to implement effective, low-false-positive rules. Such development work is typically performed by experienced Tier 2 or Tier 3 security engineers or analysts who focus on improving the SOC's overall detection posture.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.