Courseiva

ISC · domain

Security Operations

Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Security Operations practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

36 questions13 easy12 medium11 hard

Focused practice

Practice Security Operations questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Operations

Security Operations questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Operations exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security Operations questions (36)

Click any question to see the full explanation, or start a practice session above.

1

Which component in the MITRE ATT&CK framework should be mapped to an SOC alerting rule to ensure the alert covers a specific adversary objective?

Easy
2

In Splunk Enterprise Security, which dashboard should the SOC manager review to evaluate the effectiveness of the current correlation searches and the volume of notable events?

Easy
3

Which THREE pieces of information should be included in an 'Incident Notification' for executive stakeholders?

Medium
4

A security analyst is troubleshooting a failed connection to an internal application that is protected by Zscaler Private Access (ZPA). Which tool should the analyst use to verify if the policy is blocking the request?

Hard
5

Which TWO data sources are most critical for detecting lateral movement within a corporate network?

Easy
6

Which THREE types of data should be ingested by a SIEM to improve its threat detection capabilities?

Medium
7

An organization uses Microsoft Sentinel. To ensure that an automated incident response playbook only triggers when a high-severity alert originates from a specific production subnet, where should the condition be defined?

Medium
8

When managing a FortiGate firewall, which feature allows the SOC to dynamically update network objects based on external threat feeds?

Medium
9

In the context of the Google Cloud Security Command Center (SCC), which feature provides a prioritized list of findings based on the criticality of the impacted asset?

Medium
10

Which SOC process ensures that all security tools are configured to log at the same time standard to prevent confusion during timeline analysis?

Easy
11

When configuring CrowdStrike Falcon to isolate a host during an active incident, what is the prerequisite requirement for the agent's communication state?

Hard
12

Which THREE actions should be taken when performing an incident post-mortem according to industry best practices?

Hard
13

Which TWO of the following are primary components of an effective Incident Response (IR) program?

Easy
14

In Okta, to restrict administrative access to a specific geographic region during an active session, which policy should be modified?

Medium
15

In Rapid7 InsightVM, what is the best way to categorize assets into groups based on their business function for targeted vulnerability reporting?

Medium
16

Which THREE technical controls are effective for limiting the impact of lateral movement?

Hard
17

Which TWO of the following are considered 'Indicator of Compromise' (IOC) types?

Easy
18

An organization is investigating a potential lateral movement incident in AWS. Which CloudTrail event field provides the most reliable indicator of the source IP address for an API call performed by an IAM role?

Hard
19

When configuring a Cisco ASA firewall to log deny events to a remote Syslog server, what is the minimum logging level required to ensure that denied packets are captured?

Hard
20

Which THREE activities are included in the 'Preparation' phase of the IR life cycle?

Medium
21

When configuring a Qualys scanner to perform authenticated scans on Windows, what is the 'Windows Authentication Record' primarily used for?

Hard
22

Which TWO communication channels are typically used for emergency incident coordination within a SOC?

Easy
23

During an incident, which document is used by the SOC to record evidence, timestamps, and actions taken to ensure admissibility in a legal proceeding?

Easy
24

When using Palo Alto Networks Cortex XSOAR, which component is responsible for orchestrating the execution of scripts across multiple third-party integrations?

Medium
25

In an incident response plan, which metric is most useful for measuring the 'dwell time' of a threat actor?

Easy
26

Which phase of the NIST Incident Response Life Cycle involves activities like system sanitization and validation of system integrity?

Easy
27

Which THREE factors are required to calculate the 'Risk' of a vulnerability for reporting purposes?

Hard
28

In VMware Carbon Black Cloud, which feature should be enabled to block unauthorized scripts while allowing signed binaries from trusted software vendors?

Medium
29

In Tenable.io, when prioritizing vulnerability remediation, which metric provides the best insight into the likelihood of a vulnerability being exploited in the wild?

Medium
30

Which document describes the specific steps an analyst should take when a 'Phishing' alert is triggered in the SIEM?

Easy
31

When implementing FIM (File Integrity Monitoring) in Tripwire Enterprise, what is the specific purpose of a 'Promotion' action?

Hard
32

When analyzing network traffic in Wireshark for potential exfiltration, what specific filter allows you to isolate TCP traffic where the payload size exceeds 10MB?

Hard
33

Which SOC metric is most appropriate to present to executive leadership to demonstrate the business value of security investments?

Easy
34

Which TWO metrics are essential for evaluating the performance of a SOC team in identifying and containing threats?

Medium
35

Which document is considered the primary 'source of truth' for defining the SOC's roles, responsibilities, and communication paths during a major security incident?

Easy
36

A Microsoft Entra ID (Azure AD) user account is suspected of compromise. What is the most effective way to invalidate all active session tokens immediately?

Hard

Frequently asked questions

What does the Security Operations domain cover on the ISC exam?
Security Operations questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 36 Security Operations questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Operations questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
(ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Security Operations Practice Questions