CISSP · domain
Security Operations
Security Operations covers day-to-day monitoring, detection, response, and recovery: logging and SIEM correlation, incident response phases and team roles, digital forensics and evidence handling, BCP/DR metrics like RTO/RPO, and vulnerability and patch management. Questions are scenario-based, asking you to classify incidents, pick the right role, metric, or prioritization criterion.
Focused practice
Practice Security Operations questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Operations
Be able to read a scenario and classify it: incident type, correct IR role, right BCP/DR metric, or best remediation priority. The single most important thing is matching the question's ask (detect, respond, recover, or prioritize) to the correct concept, not the most technical answer.
SIEM correlation rules and log sources for detecting brute-force, credential stuffing, and impossible-travel events
Incident response team roles: incident commander, communications lead, and liaison to media and regulators
BCP/DR metrics: RTO, RPO, MTD, and MTBF applied to recovery planning and backup design
Vulnerability management prioritization using CVSS scores, asset criticality, and exploit availability
Watch out for
Common Security Operations exam traps
- ▸Confusing RTO with RPO: RTO is acceptable downtime, RPO is acceptable data loss measured in time.
- ▸Choosing technical containment steps when the question asks who communicates with media or regulators.
- ▸Treating every failed-login burst as a breach instead of recognizing it as a precursor or brute-force attempt.
Question index
All Security Operations questions (54)
Click any question to see the full explanation, or start a practice session above.
A business continuity plan (BCP) differs from a disaster recovery plan (DRP) in that the BCP primarily focuses on:
Medium2A security analyst is configuring a SIEM to improve threat detection. Which THREE of the following are essential capabilities of a SIEM system?
Hard3An organization wants to ensure that its critical database can be restored to a point within the last 15 minutes in case of failure. Which metric defines this requirement?
Medium4A security team is implementing data loss prevention (DLP) to protect sensitive information. Which DLP type is best suited to monitor and block sensitive data leaving the corporate network via email or web traffic?
Medium5A SOC analyst receives an alert from the SIEM indicating a large volume of outbound data from a sensitive database server to an external IP address. The analyst queries the SIEM and finds the server communicated with the external IP during non-business hours. Which type of incident is most likely occurring?
Hard6A security analyst is selecting forensic tools for an investigation. Which TWO tools are best suited for memory forensics? (Select TWO.)
Medium7During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?
Medium8An organization has a maximum tolerable downtime (MTD) of 8 hours for its critical e-commerce platform. The recovery time objective (RTO) is set to 4 hours, and the recovery point objective (RPO) is 30 minutes. Which disaster recovery strategy is most cost-effective while meeting these requirements?
Hard9A security team implements a Data Loss Prevention (DLP) solution to monitor email attachments for sensitive data. Which type of DLP is being used?
Medium10Which of the following best describes the primary purpose of an incident response plan?
Easy11A company is evaluating disaster recovery strategies and wants to minimize both RTO and RPO. Which THREE options provide the best combination of low RTO and low RPO? (Select THREE)
Hard12Which role in an incident response team is primarily responsible for coordinating communication with external parties, such as the media and regulators?
Easy13A security analyst is reviewing SIEM logs and notices multiple failed login attempts from a single IP address followed by a successful login. The account belongs to a user in finance. Which incident category is most appropriate?
Medium14Which metric defines the maximum amount of data loss an organization can tolerate during a disaster?
Easy15An organization is developing an incident response plan. Which component is responsible for defining the specific conditions that constitute an incident?
Easy16An organization is implementing a change management process. Which group is responsible for reviewing and approving major changes?
Medium17A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?
Easy18An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)
Medium19A SOC team is using a SIEM to correlate events from multiple sources. They want to automate responses to common threats. Which technology should they integrate to achieve security orchestration and automation?
Medium20Which of the following is the primary purpose of a Change Advisory Board (CAB)?
Medium21An organization is developing an incident response plan. Which component is primarily responsible for defining the criteria for escalating an incident to senior management and legal counsel?
Medium22A SOC manager is designing a tiered incident response team. Which THREE of the following are standard roles in an incident response team according to industry best practices?
Medium23An organization has a maximum tolerable downtime (MTD) of 8 hours for a critical application. The recovery time objective (RTO) is set to 4 hours. Which of the following best describes the purpose of the RTO?
Easy24Which of the following metrics is used to determine the maximum amount of data loss an organization can tolerate in a disaster?
Easy25Which of the following is an example of a social engineering attack?
Easy26Which of the following is the most important factor when prioritizing vulnerability remediation in a vulnerability management program?
Hard27An organization's disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours for its critical financial application. Which disaster recovery site would be MOST appropriate to meet this RTO?
Medium28What type of DLP system monitors data in motion across the network?
Easy29During a forensic investigation, an analyst must collect volatile data in the correct order. Which of the following sequences correctly follows the order of volatility?
Hard30During a forensic investigation, the investigator must ensure that evidence is properly handled and documented. What is the primary purpose of maintaining a chain of custody?
Medium31Which digital forensics tool is specifically designed for memory forensics?
Easy32A hospital's security operations center receives an alert that a nurse's workstation is communicating with a known command-and-control IP address. The analyst confirms the workstation is infected with malware that is beaconing every sixty seconds. Following the incident response process, which action should the analyst take FIRST?
Easy33During a forensic investigation, which TWO of the following are essential steps to maintain chain of custody?
Medium34A company is designing a disaster recovery strategy for its e-commerce platform. The platform requires an RTO of 2 hours and an RPO of 15 minutes. Which TWO strategies would BEST meet these requirements?
Hard35What is the primary purpose of a Change Advisory Board (CAB) in change management?
Medium36An organization's security operations center (SOC) uses a SIEM to correlate logs. The SOC manager wants to automate response actions for low-severity alerts. Which technology would best support this goal?
Medium37A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?
Medium38Which of the following BEST describes the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
Easy39An organization is designing its incident response team roles. Which role is primarily responsible for collecting and preserving evidence for legal proceedings?
Hard40A company is selecting a disaster recovery site for critical applications that must be restored within 4 hours with minimal data loss. Which site type best meets these requirements?
Medium41An organization is planning its disaster recovery strategy. Which THREE options are considered recovery site types? (Select THREE.)
Medium42A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should the investigator capture FIRST?
Hard43An organization is implementing a patch management process. Which of the following is the most critical step to ensure that patches do not disrupt critical business operations?
Hard44Which of the following is a key difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
Easy45During a digital forensics investigation, which of the following data sources has the highest order of volatility?
Medium46Which type of digital forensics involves capturing and analyzing network traffic to investigate a security incident?
Easy47An organization is updating its incident response plan. According to best practices, which THREE components should be included in the plan?
Medium48A company plans to implement a disaster recovery site that can be operational within 2 hours of a failure. Which type of DR site best meets this requirement?
Hard49A company is selecting a disaster recovery strategy for a mission-critical application. Which TWO of the following strategies provide the shortest recovery time objective (RTO)?
Hard50A security analyst is examining a memory dump from a compromised workstation. Which TWO tools are commonly used for memory forensics?
Medium51What is the PRIMARY purpose of a chain of custody in digital forensics?
Easy52A security administrator is reviewing the logging configuration for a fleet of Linux servers that host a regulated payment application. An external auditor requires that the servers produce a tamper-evident record of all authentication events, including successful and failed logons, and that the record be retained for one year. Which action BEST satisfies the auditor's requirement?
Medium53A SOC analyst at Tier 1 identifies a potential malware infection on a user workstation. What is the next step in the standard incident response process?
Medium54A security analyst is identifying incident categories for a new incident response plan. Which TWO of the following are valid incident categories according to standard IR frameworks?
MediumOther domains
All CISSP exam domains
Frequently asked questions
- What does the Security Operations domain cover on the CISSP exam?
- Be able to read a scenario and classify it: incident type, correct IR role, right BCP/DR metric, or best remediation priority. The single most important thing is matching the question's ask (detect, respond, recover, or prioritize) to the correct concept, not the most technical answer.
- How many questions are in this domain?
- This page lists all 54 Security Operations questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Operations questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.