โ† All CCP Flashcard Decks

SOC Operations & Alert Triage Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 SOC Operations & Alert Triage flashcards as text
  1. An analyst notices PowerShell commands with Base64-encoded arguments in endpoint logs. What is the MOST appropriate immediate action?

    Answer: Isolate the host and escalate for deeper investigation

    Base64-encoded PowerShell is a common obfuscation technique used by attackers, warranting host isolation and escalation to prevent further compromise.

  2. Which framework is MOST commonly used by SOC teams to map adversary tactics and techniques during alert triage?

    Answer: MITRE ATT&CK

    MITRE ATT&CK provides a structured knowledge base of adversary tactics and techniques that SOC teams use to classify and contextualize observed behaviors.

  3. A SOC receives an alert that a user downloaded an executable from a file-sharing site. Which data source BEST helps determine if the file is malicious?

    Answer: Threat intelligence feed and file hash lookup

    Cross-referencing the file's hash against threat intelligence feeds and reputation databases provides rapid malware classification.

  4. What does 'dwell time' refer to in the context of SOC operations?

    Answer: Duration between initial compromise and threat detection

    Dwell time is the period an attacker remains undetected within a network after initial compromise, and reducing it is a key SOC goal.

  5. Which type of analysis involves examining the behavior of a suspicious file in a controlled, isolated environment?

    Answer: Dynamic (sandbox) analysis

    Dynamic or sandbox analysis executes the suspicious file in an isolated environment to observe its runtime behavior without risking production systems.

  6. During triage, an analyst identifies an internal host communicating with a known C2 IP address. What is the recommended FIRST step?

    Answer: Block the C2 IP at the perimeter and isolate the host for investigation

    Blocking the C2 channel at the perimeter cuts the attacker's control while isolating the host prevents further internal spread.

  7. Which SOC tier is PRIMARILY responsible for initial alert monitoring and triage?

    Answer: Tier 1 (Level 1 Analyst)

    Tier 1 analysts perform initial alert monitoring, triaging incoming events and escalating confirmed or suspicious incidents to higher tiers.