CISSP Security Operations Practice Question
An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)
⚠ Common exam trap
CISSP often tests the boundaries between SOC tiers, so candidates assign advanced tasks like threat hunting or detection engineering to Tier 1 when those belong to Tier 2 or Tier 3.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Monitoring SIEM alerts and performing initial triage
Option B is correct because Tier 1 analysts are the first line of defense in a SOC, continuously monitoring SIEM alerts and performing initial triage to determine whether an alert is a true positive, false positive, or benign event. Option C is correct because a core Tier 1 responsibility is escalating validated or suspicious incidents to Tier 2 for deeper investigation when the alert exceeds their scope or requires advanced analysis. Threat hunting (A) is typically performed by Tier 2 or Tier 3 analysts who proactively search for hidden threats rather than react to alerts. In-depth forensic analysis (D) is a Tier 3 or dedicated incident response function requiring specialized tools and expertise. Developing new detection rules for the SIEM (E) is usually the responsibility of Tier 2/Tier 3 analysts or detection engineers, not Tier 1.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Performing threat hunting
Why it's wrong here
Threat hunting is a proactive security discipline focused on seeking out unknown threats that have evaded existing security controls. This advanced activity requires specialized skills in data analysis, hypothesis generation, and deep understanding of adversary tactics, techniques, and procedures (TTPs), making it a responsibility for more experienced Tier 2 or Tier 3 analysts, not the initial reactive duties of Tier 1.
- ✓
Monitoring SIEM alerts and performing initial triage
Why this is correct
Tier 1 SOC analysts are primarily responsible for the continuous monitoring of security information and event management (SIEM) systems. Their core duty involves reviewing incoming alerts, correlating events, and performing an initial assessment to determine if an alert represents a legitimate security incident. This initial triage ensures that potential threats are identified promptly and categorized for appropriate next steps.
- ✓
Escalating incidents to Tier 2 when necessary
Why this is correct
A critical function of Tier 1 analysts is to recognize when an incident exceeds their defined scope of resolution or requires more in-depth investigation. When an alert is validated as a true positive and cannot be resolved using standard operating procedures or requires specialized expertise, Tier 1 personnel are responsible for accurately documenting and escalating the incident to Tier 2. This ensures that complex or critical incidents receive the necessary advanced attention without delay.
- ✗
Conducting in-depth forensic analysis
Why it's wrong here
In-depth forensic analysis involves meticulously examining digital evidence from compromised systems, networks, or applications to reconstruct events, identify root causes, and gather intelligence for legal or remediation purposes. This highly specialized task requires advanced expertise in forensic tools, operating system internals, memory analysis, and legal chain-of-custody procedures. Such complex investigations are typically reserved for highly skilled Tier 3 incident responders or dedicated forensic specialists, far beyond the initial response capabilities of Tier 1.
- ✗
Developing new detection rules for the SIEM
Why it's wrong here
The creation and refinement of new detection rules for a SIEM system involve a deep understanding of log sources, threat intelligence, attack patterns, and the specific query language of the SIEM platform. This proactive engineering task requires analytical skills to identify gaps in current detection capabilities and the technical expertise to implement effective, low-false-positive rules. Such development work is typically performed by experienced Tier 2 or Tier 3 security engineers or analysts who focus on improving the SOC's overall detection posture.
Go deeper
Related to this question
Learn chapter
Security Operations Foundations
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.