โ† All CCP Flashcard Decks

Security Operations & Incident Response Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Operations & Incident Response flashcards as text
  1. Which incident response phase involves restoring affected systems to normal operations while verifying no threats remain?

    Answer: Recovery

    The Recovery phase restores systems from clean backups or rebuilds and validates normal function after eradication of the threat.

  2. A SOC team receives an alert for an unusually high volume of LDAP queries from a single workstation. This activity is MOST consistent with:

    Answer: Active Directory enumeration for lateral movement or privilege escalation

    Bulk LDAP enumeration is a classic technique attackers use to map the Active Directory environment and identify high-value targets.

  3. In network forensics, what is the MAIN advantage of capturing full packet data (PCAP) over NetFlow records?

    Answer: PCAPs contain complete payload data enabling deep content inspection

    Full packet captures retain payload content, allowing analysts to reconstruct sessions and inspect commands, while NetFlow only records metadata.

  4. When a SOC analyst 'pivots' during threat hunting, they are:

    Answer: Using one discovered artifact to search for related indicators across the environment

    Pivoting expands investigation by using a known IOC (e.g., an IP, hash, or username) as a starting point to uncover connected malicious activity.

  5. Which of the following is a PRIMARY security concern with using public threat intelligence sharing platforms?

    Answer: Sharing your IOCs may reveal your detection capabilities to adversaries

    Publishing your specific IOCs can inform adversaries about what you can detect, allowing them to modify their TTPs to evade your defenses.

  6. A security analyst is reviewing an email header and notices the 'Received-SPF' field shows 'fail.' This MOST likely indicates:

    Answer: The sending server is not authorized to send email for the domain in the 'From' field

    An SPF fail means the sending IP address is not listed in the domain's SPF DNS record, a common sign of email spoofing.

  7. What is the PRIMARY purpose of a 'tabletop exercise' in an incident response program?

    Answer: To walk stakeholders through a hypothetical scenario to test plans and decision-making

    Tabletop exercises are discussion-based simulations that expose gaps in IR plans and communication without touching live systems.