SOC Operations & Alert Triage Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 SOC Operations & Alert Triage flashcards as text
A SOC analyst receives an alert for a scheduled task created on a server at 3 AM by a service account. What is the BEST initial triage action?
Answer: Verify if the task creation is authorized and matches known change management records
Verifying authorization against change management records determines if the scheduled task is a legitimate maintenance operation or an attacker establishing persistence.
Which of the following BEST defines 'Mean Time to Respond (MTTR)' in a SOC context?
Answer: Average time from alert detection to full incident containment and remediation
MTTR measures the average time elapsed between detecting an incident and fully containing and remediating it, reflecting SOC response effectiveness.
What is the significance of detecting the tool 'Mimikatz' in endpoint telemetry?
Answer: It signals likely credential harvesting activity by an attacker
Mimikatz is a well-known credential dumping tool commonly used by attackers to extract passwords and hashes from Windows memory.
A SOC analyst needs to prioritize five simultaneous alerts. Which factor should carry the MOST weight in prioritization?
Answer: The criticality of the affected asset combined with the severity of the potential threat
Effective alert prioritization weighs both asset criticality (business impact) and threat severity to focus resources on the highest-risk incidents first.
Which practice BEST helps a SOC maintain situational awareness of the current threat landscape?
Answer: Consuming and operationalizing threat intelligence feeds relevant to the organization's sector
Operationalizing relevant threat intelligence feeds keeps SOC teams informed of active campaigns, actor TTPs, and indicators targeting their industry.
What is a 'false negative' in the context of SOC detection?
Answer: A real attack that occurred but generated no alert
A false negative occurs when a genuine attack or malicious activity takes place but is not detected or alerted upon by security controls.
Which technique do attackers commonly use to evade detection when exfiltrating data through allowed channels?
Answer: Steganography or encoding data within legitimate-looking HTTPS or DNS traffic
Encoding or hiding data within legitimate protocols like HTTPS or DNS allows attackers to blend exfiltration traffic with normal network activity and evade inspection.