Courseiva

CISSP · domain

Security Operations

Security Operations covers day-to-day monitoring, detection, response, and recovery: logging and SIEM correlation, incident response phases and team roles, digital forensics and evidence handling, BCP/DR metrics like RTO/RPO, and vulnerability and patch management. Questions are scenario-based, asking you to classify incidents, pick the right role, metric, or prioritization criterion.

54 questions15 easy27 medium12 hard

Focused practice

Practice Security Operations questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Operations

Be able to read a scenario and classify it: incident type, correct IR role, right BCP/DR metric, or best remediation priority. The single most important thing is matching the question's ask (detect, respond, recover, or prioritize) to the correct concept, not the most technical answer.

SIEM correlation rules and log sources for detecting brute-force, credential stuffing, and impossible-travel events

Incident response team roles: incident commander, communications lead, and liaison to media and regulators

BCP/DR metrics: RTO, RPO, MTD, and MTBF applied to recovery planning and backup design

Vulnerability management prioritization using CVSS scores, asset criticality, and exploit availability

Watch out for

Common Security Operations exam traps

  • ▸Confusing RTO with RPO: RTO is acceptable downtime, RPO is acceptable data loss measured in time.
  • ▸Choosing technical containment steps when the question asks who communicates with media or regulators.
  • ▸Treating every failed-login burst as a breach instead of recognizing it as a precursor or brute-force attempt.

Question index

All Security Operations questions (54)

Click any question to see the full explanation, or start a practice session above.

1

A business continuity plan (BCP) differs from a disaster recovery plan (DRP) in that the BCP primarily focuses on:

Medium
2

A security analyst is configuring a SIEM to improve threat detection. Which THREE of the following are essential capabilities of a SIEM system?

Hard
3

An organization wants to ensure that its critical database can be restored to a point within the last 15 minutes in case of failure. Which metric defines this requirement?

Medium
4

A security team is implementing data loss prevention (DLP) to protect sensitive information. Which DLP type is best suited to monitor and block sensitive data leaving the corporate network via email or web traffic?

Medium
5

A SOC analyst receives an alert from the SIEM indicating a large volume of outbound data from a sensitive database server to an external IP address. The analyst queries the SIEM and finds the server communicated with the external IP during non-business hours. Which type of incident is most likely occurring?

Hard
6

A security analyst is selecting forensic tools for an investigation. Which TWO tools are best suited for memory forensics? (Select TWO.)

Medium
7

During a vulnerability management lifecycle, after vulnerabilities are identified and prioritized, what is the NEXT step?

Medium
8

An organization has a maximum tolerable downtime (MTD) of 8 hours for its critical e-commerce platform. The recovery time objective (RTO) is set to 4 hours, and the recovery point objective (RPO) is 30 minutes. Which disaster recovery strategy is most cost-effective while meeting these requirements?

Hard
9

A security team implements a Data Loss Prevention (DLP) solution to monitor email attachments for sensitive data. Which type of DLP is being used?

Medium
10

Which of the following best describes the primary purpose of an incident response plan?

Easy
11

A company is evaluating disaster recovery strategies and wants to minimize both RTO and RPO. Which THREE options provide the best combination of low RTO and low RPO? (Select THREE)

Hard
12

Which role in an incident response team is primarily responsible for coordinating communication with external parties, such as the media and regulators?

Easy
13

A security analyst is reviewing SIEM logs and notices multiple failed login attempts from a single IP address followed by a successful login. The account belongs to a user in finance. Which incident category is most appropriate?

Medium
14

Which metric defines the maximum amount of data loss an organization can tolerate during a disaster?

Easy
15

An organization is developing an incident response plan. Which component is responsible for defining the specific conditions that constitute an incident?

Easy
16

An organization is implementing a change management process. Which group is responsible for reviewing and approving major changes?

Medium
17

A company is implementing a Data Loss Prevention (DLP) program. Which THREE of the following are common types of DLP controls?

Easy
18

An organization is designing a security operations center (SOC) with three tiers. Which TWO of the following are typical responsibilities of Tier 1 analysts? (Select TWO)

Medium
19

A SOC team is using a SIEM to correlate events from multiple sources. They want to automate responses to common threats. Which technology should they integrate to achieve security orchestration and automation?

Medium
20

Which of the following is the primary purpose of a Change Advisory Board (CAB)?

Medium
21

An organization is developing an incident response plan. Which component is primarily responsible for defining the criteria for escalating an incident to senior management and legal counsel?

Medium
22

A SOC manager is designing a tiered incident response team. Which THREE of the following are standard roles in an incident response team according to industry best practices?

Medium
23

An organization has a maximum tolerable downtime (MTD) of 8 hours for a critical application. The recovery time objective (RTO) is set to 4 hours. Which of the following best describes the purpose of the RTO?

Easy
24

Which of the following metrics is used to determine the maximum amount of data loss an organization can tolerate in a disaster?

Easy
25

Which of the following is an example of a social engineering attack?

Easy
26

Which of the following is the most important factor when prioritizing vulnerability remediation in a vulnerability management program?

Hard
27

An organization's disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours for its critical financial application. Which disaster recovery site would be MOST appropriate to meet this RTO?

Medium
28

What type of DLP system monitors data in motion across the network?

Easy
29

During a forensic investigation, an analyst must collect volatile data in the correct order. Which of the following sequences correctly follows the order of volatility?

Hard
30

During a forensic investigation, the investigator must ensure that evidence is properly handled and documented. What is the primary purpose of maintaining a chain of custody?

Medium
31

Which digital forensics tool is specifically designed for memory forensics?

Easy
32

A hospital's security operations center receives an alert that a nurse's workstation is communicating with a known command-and-control IP address. The analyst confirms the workstation is infected with malware that is beaconing every sixty seconds. Following the incident response process, which action should the analyst take FIRST?

Easy
33

During a forensic investigation, which TWO of the following are essential steps to maintain chain of custody?

Medium
34

A company is designing a disaster recovery strategy for its e-commerce platform. The platform requires an RTO of 2 hours and an RPO of 15 minutes. Which TWO strategies would BEST meet these requirements?

Hard
35

What is the primary purpose of a Change Advisory Board (CAB) in change management?

Medium
36

An organization's security operations center (SOC) uses a SIEM to correlate logs. The SOC manager wants to automate response actions for low-severity alerts. Which technology would best support this goal?

Medium
37

A SOC has three tiers: Tier 1 triages alerts, Tier 2 investigates, and Tier 3 performs advanced analysis. An alert about a potential data exfiltration using DNS tunneling is escalated from Tier 1. Which tier is BEST suited to perform deep packet inspection and memory forensics to confirm the exfiltration?

Medium
38

Which of the following BEST describes the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

Easy
39

An organization is designing its incident response team roles. Which role is primarily responsible for collecting and preserving evidence for legal proceedings?

Hard
40

A company is selecting a disaster recovery site for critical applications that must be restored within 4 hours with minimal data loss. Which site type best meets these requirements?

Medium
41

An organization is planning its disaster recovery strategy. Which THREE options are considered recovery site types? (Select THREE.)

Medium
42

A forensic investigator arrives at a crime scene involving a compromised server. The server is still running. According to the order of volatility, which of the following should the investigator capture FIRST?

Hard
43

An organization is implementing a patch management process. Which of the following is the most critical step to ensure that patches do not disrupt critical business operations?

Hard
44

Which of the following is a key difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

Easy
45

During a digital forensics investigation, which of the following data sources has the highest order of volatility?

Medium
46

Which type of digital forensics involves capturing and analyzing network traffic to investigate a security incident?

Easy
47

An organization is updating its incident response plan. According to best practices, which THREE components should be included in the plan?

Medium
48

A company plans to implement a disaster recovery site that can be operational within 2 hours of a failure. Which type of DR site best meets this requirement?

Hard
49

A company is selecting a disaster recovery strategy for a mission-critical application. Which TWO of the following strategies provide the shortest recovery time objective (RTO)?

Hard
50

A security analyst is examining a memory dump from a compromised workstation. Which TWO tools are commonly used for memory forensics?

Medium
51

What is the PRIMARY purpose of a chain of custody in digital forensics?

Easy
52

A security administrator is reviewing the logging configuration for a fleet of Linux servers that host a regulated payment application. An external auditor requires that the servers produce a tamper-evident record of all authentication events, including successful and failed logons, and that the record be retained for one year. Which action BEST satisfies the auditor's requirement?

Medium
53

A SOC analyst at Tier 1 identifies a potential malware infection on a user workstation. What is the next step in the standard incident response process?

Medium
54

A security analyst is identifying incident categories for a new incident response plan. Which TWO of the following are valid incident categories according to standard IR frameworks?

Medium

Frequently asked questions

What does the Security Operations domain cover on the CISSP exam?
Be able to read a scenario and classify it: incident type, correct IR role, right BCP/DR metric, or best remediation priority. The single most important thing is matching the question's ask (detect, respond, recover, or prioritize) to the correct concept, not the most technical answer.
How many questions are in this domain?
This page lists all 54 Security Operations questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Operations questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cissp ISC2-CISSP cissp security ops Practice Questions