Security Operations & Incident Response Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Operations & Incident Response flashcards as text
Which of the following BEST describes the difference between a 'false positive' and a 'false negative' in intrusion detection?
Answer: A false positive alerts on benign activity; a false negative fails to alert on real attacks
False positives create alert fatigue by flagging legitimate activity, while false negatives are more dangerous as real threats go undetected.
When performing memory forensics on a compromised Windows host, which tool is commonly used to capture a volatile memory image?
Answer: WinPmem / DumpIt
WinPmem and DumpIt are live memory acquisition tools that capture a raw memory image; Volatility is then used to analyze the resulting dump.
A security analyst discovers that an attacker used 'living off the land' techniques. This MOST likely means the attacker:
Answer: Used legitimate OS tools like PowerShell and WMI to avoid detection
Living-off-the-land attacks leverage built-in OS utilities to blend in with normal operations and evade signature-based defenses.
The MITRE ATT&CK framework is PRIMARILY used by SOC teams to:
Answer: Map observed adversary behaviors to known tactics and techniques
ATT&CK provides a structured taxonomy of adversary TTPs that analysts use to categorize detections and identify coverage gaps.
During incident triage, what does 'scoping' refer to?
Answer: Determining the full extent of systems and data affected by the incident
Scoping defines the blast radius of an incident by identifying all compromised assets, accounts, and data to guide containment and remediation.
Which artifact would BEST help determine user activity on a Windows system during a specific timeframe?
Answer: Windows Event Log (Security.evtx) combined with prefetch files
Security event logs record logon/logoff and process activity, while prefetch files show recently executed programs, together providing a timeline of user activity.
A threat intelligence feed reports a new IOC (Indicator of Compromise). The FIRST action a SOC analyst should take is to:
Answer: Search historical logs to determine if the IOC has already appeared in the environment
Retroactive hunting against historical data reveals whether the threat actor already operated in the environment before defenses were updated.