ISC · domain
Security Operations
Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Security Operations practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Security Operations questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Operations
Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Security Operations exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Security Operations questions (36)
Click any question to see the full explanation, or start a practice session above.
Which component in the MITRE ATT&CK framework should be mapped to an SOC alerting rule to ensure the alert covers a specific adversary objective?
Easy2In Splunk Enterprise Security, which dashboard should the SOC manager review to evaluate the effectiveness of the current correlation searches and the volume of notable events?
Easy3Which THREE pieces of information should be included in an 'Incident Notification' for executive stakeholders?
Medium4A security analyst is troubleshooting a failed connection to an internal application that is protected by Zscaler Private Access (ZPA). Which tool should the analyst use to verify if the policy is blocking the request?
Hard5Which TWO data sources are most critical for detecting lateral movement within a corporate network?
Easy6Which THREE types of data should be ingested by a SIEM to improve its threat detection capabilities?
Medium7An organization uses Microsoft Sentinel. To ensure that an automated incident response playbook only triggers when a high-severity alert originates from a specific production subnet, where should the condition be defined?
Medium8When managing a FortiGate firewall, which feature allows the SOC to dynamically update network objects based on external threat feeds?
Medium9In the context of the Google Cloud Security Command Center (SCC), which feature provides a prioritized list of findings based on the criticality of the impacted asset?
Medium10Which SOC process ensures that all security tools are configured to log at the same time standard to prevent confusion during timeline analysis?
Easy11When configuring CrowdStrike Falcon to isolate a host during an active incident, what is the prerequisite requirement for the agent's communication state?
Hard12Which THREE actions should be taken when performing an incident post-mortem according to industry best practices?
Hard13Which TWO of the following are primary components of an effective Incident Response (IR) program?
Easy14In Okta, to restrict administrative access to a specific geographic region during an active session, which policy should be modified?
Medium15In Rapid7 InsightVM, what is the best way to categorize assets into groups based on their business function for targeted vulnerability reporting?
Medium16Which THREE technical controls are effective for limiting the impact of lateral movement?
Hard17Which TWO of the following are considered 'Indicator of Compromise' (IOC) types?
Easy18An organization is investigating a potential lateral movement incident in AWS. Which CloudTrail event field provides the most reliable indicator of the source IP address for an API call performed by an IAM role?
Hard19When configuring a Cisco ASA firewall to log deny events to a remote Syslog server, what is the minimum logging level required to ensure that denied packets are captured?
Hard20Which THREE activities are included in the 'Preparation' phase of the IR life cycle?
Medium21When configuring a Qualys scanner to perform authenticated scans on Windows, what is the 'Windows Authentication Record' primarily used for?
Hard22Which TWO communication channels are typically used for emergency incident coordination within a SOC?
Easy23During an incident, which document is used by the SOC to record evidence, timestamps, and actions taken to ensure admissibility in a legal proceeding?
Easy24When using Palo Alto Networks Cortex XSOAR, which component is responsible for orchestrating the execution of scripts across multiple third-party integrations?
Medium25In an incident response plan, which metric is most useful for measuring the 'dwell time' of a threat actor?
Easy26Which phase of the NIST Incident Response Life Cycle involves activities like system sanitization and validation of system integrity?
Easy27Which THREE factors are required to calculate the 'Risk' of a vulnerability for reporting purposes?
Hard28In VMware Carbon Black Cloud, which feature should be enabled to block unauthorized scripts while allowing signed binaries from trusted software vendors?
Medium29In Tenable.io, when prioritizing vulnerability remediation, which metric provides the best insight into the likelihood of a vulnerability being exploited in the wild?
Medium30Which document describes the specific steps an analyst should take when a 'Phishing' alert is triggered in the SIEM?
Easy31When implementing FIM (File Integrity Monitoring) in Tripwire Enterprise, what is the specific purpose of a 'Promotion' action?
Hard32When analyzing network traffic in Wireshark for potential exfiltration, what specific filter allows you to isolate TCP traffic where the payload size exceeds 10MB?
Hard33Which SOC metric is most appropriate to present to executive leadership to demonstrate the business value of security investments?
Easy34Which TWO metrics are essential for evaluating the performance of a SOC team in identifying and containing threats?
Medium35Which document is considered the primary 'source of truth' for defining the SOC's roles, responsibilities, and communication paths during a major security incident?
Easy36A Microsoft Entra ID (Azure AD) user account is suspected of compromise. What is the most effective way to invalidate all active session tokens immediately?
HardOther domains
All ISC exam domains
Frequently asked questions
- What does the Security Operations domain cover on the ISC exam?
- Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 36 Security Operations questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Operations questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.