SIEM & Threat Detection Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 SIEM & Threat Detection flashcards as text
What is a Security Orchestration, Automation, and Response (SOAR) platform's primary advantage over a standalone SIEM?
Answer: SOAR automates response actions and integrates workflows to reduce manual analyst effort
SOAR platforms automate repetitive response tasks (like blocking IPs or isolating hosts) and orchestrate cross-tool workflows, significantly reducing analyst workload and response time.
During a threat hunt, an analyst searches for processes making DNS queries to randomly generated domain names. What threat does this technique help identify?
Answer: Domain Generation Algorithm (DGA) malware
Domain Generation Algorithms (DGAs) are used by malware to generate many pseudo-random domain names as potential C2 contact points, making them hard to blacklist.
What does a high false negative rate in a SIEM indicate?
Answer: The SIEM is missing real attacks that should have been detected
A high false negative rate means the system fails to alert on actual malicious activity, leaving real threats undetected — a critical gap in security coverage.
Which log source is most valuable for detecting lateral movement within a Windows environment?
Answer: Windows Security Event logs (e.g., Event ID 4624, 4648)
Windows Security Event logs capture authentication events (logon types, source IPs, account names) that are essential for detecting lateral movement via credential reuse or pass-the-hash.
What is 'alert fatigue' in a SOC environment?
Answer: Desensitization of analysts due to an overwhelming volume of low-quality alerts
Alert fatigue occurs when analysts receive so many alerts — especially false positives — that they become desensitized and may miss genuine threats buried in the noise.
Which technique would an attacker use to avoid detection by time-based SIEM correlation rules?
Answer: Low-and-slow attack pacing to stay below detection thresholds
Low-and-slow attacks spread malicious activity over extended time periods, intentionally staying below rate-based SIEM thresholds that would trigger on rapid activity.
What is the primary function of threat intelligence feeds integrated into a SIEM?
Answer: To provide indicators of compromise (IOCs) for matching against collected log data
Threat intelligence feeds supply known malicious IOCs (IPs, domains, file hashes) that the SIEM matches against ingested logs to identify connections to known threat actors.