SOC Operations & Alert Triage Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 SOC Operations & Alert Triage flashcards as text
An analyst receives an alert for a high volume of DNS queries to a single external domain from one internal host. What is the MOST likely threat to investigate first?
Answer: DNS tunneling for data exfiltration
High-frequency DNS queries to a single domain from one host is a classic indicator of DNS tunneling used for covert data exfiltration.
Which metric is MOST useful for measuring the efficiency of a SOC's alert handling process?
Answer: Mean Time to Detect (MTTD)
Mean Time to Detect (MTTD) measures how quickly a SOC identifies a threat, directly reflecting detection efficiency.
A SOC analyst observes repeated failed login attempts followed by one successful login from the same IP. What triage step should be performed FIRST?
Answer: Check if the successful login belongs to an authorized user
Verifying whether the successful login is from a legitimate user determines if a credential stuffing or brute-force attack succeeded.
In a SOC workflow, what is the purpose of a playbook?
Answer: To provide step-by-step response procedures for specific alert types
Playbooks provide standardized, step-by-step procedures analysts follow when responding to specific types of security alerts.
Which of the following BEST describes a 'true positive' in SOC alert triage?
Answer: An alert that correctly identifies actual malicious activity
A true positive is an alert that accurately flags genuine malicious or unauthorized activity requiring analyst attention.
A SOC team wants to reduce alert fatigue. Which approach is MOST effective?
Answer: Tune SIEM rules to suppress known benign events
Tuning SIEM rules to filter out known benign patterns reduces noise so analysts focus on genuine threats.
Which log source is MOST valuable for detecting lateral movement within a Windows environment?
Answer: Windows Security Event Logs (Event ID 4624/4648)
Windows Security Event IDs 4624 (logon) and 4648 (explicit credential use) capture authentication events critical for detecting lateral movement.