โ† All CCP Flashcard Decks

Security Operations & Incident Response Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Operations & Incident Response flashcards as text
  1. Which technique is MOST effective for detecting fileless malware that executes entirely in memory?

    Answer: Behavioral monitoring of process memory and anomalous script execution

    Fileless malware leaves no disk artifacts, so behavioral detection of suspicious process behavior and in-memory script execution is necessary.

  2. During an IR engagement, an analyst finds that the attacker established persistence via a scheduled task. Which Windows event log ID would confirm scheduled task creation?

    Answer: Event ID 4698

    Windows Security Event ID 4698 is logged when a scheduled task is created, making it the key artifact for this persistence mechanism.

  3. A 'diamond model' of intrusion analysis focuses on the relationship between which four elements?

    Answer: Adversary, capability, infrastructure, and victim

    The Diamond Model structures intrusion analysis around the four core features: adversary, capability, infrastructure, and victim, and their interrelationships.

  4. When should chain of custody documentation FIRST be initiated during a digital forensic investigation?

    Answer: Before any evidence is collected or handled

    Chain of custody must be established from the moment evidence is identified to ensure its integrity and admissibility throughout the investigation.

  5. An attacker is using 'pass-the-hash' to move laterally in a Windows environment. Which control would MOST effectively mitigate this technique?

    Answer: Implementing Credential Guard to protect NTLM hashes in a virtualized enclave

    Windows Credential Guard uses virtualization-based security to isolate credential material, preventing attackers from extracting NTLM hashes from LSASS.

  6. A SOC team is overwhelmed by alert fatigue. The BEST long-term solution is to:

    Answer: Tune detection rules and implement SOAR playbooks to reduce noise and automate responses

    Tuning reduces false positives at the source, while SOAR automation handles repetitive tasks, sustainably reducing analyst burden without missing real threats.

  7. Which of the following BEST describes the role of a 'threat hunter' compared to a traditional SOC analyst?

    Answer: Threat hunters proactively search for hidden adversaries using hypotheses rather than waiting for alerts

    Threat hunting is a proactive, hypothesis-driven discipline that assumes compromise and searches for adversaries that have evaded automated detection.