CSOC Security Operations Procedures 2 — Questions and Answers
Question 1: What is 'Security Orchestration, Automation, and Response' (SOAR) in CSOC operations?
- Technology that automates repetitive security tasks, integrates different security tools, and orchestrates incident response workflows to improve speed and efficiency (Correct answer)
- A certification programme for CSOC staff who specialise in incident response
- A framework for coordinating physical and cybersecurity teams during hybrid incidents
- A Singapore government standard for CSOC operational procedures
Correct answer: Technology that automates repetitive security tasks, integrates different security tools, and orchestrates incident response workflows to improve speed and efficiency
SOAR platforms automate routine, repetitive tasks such as alert enrichment, notification, and simple response actions, freeing analysts to focus on higher-value investigation and decision-making. They also integrate disparate security tools into unified workflows.
Question 2: What is the 'kill chain' framework in cybersecurity operations?
- A model describing the stages of a cyber attack from reconnaissance through to data exfiltration, used to understand and disrupt attacks at each stage (Correct answer)
- A chain of command structure defining who has authority to shut down systems during an attack
- A forensic process for recovering deleted data from compromised systems
- A risk scoring framework that assigns a kill probability to each identified vulnerability
Correct answer: A model describing the stages of a cyber attack from reconnaissance through to data exfiltration, used to understand and disrupt attacks at each stage
The cyber kill chain describes the sequential stages of a cyber attack: reconnaissance, weaponisation, delivery, exploitation, installation, command and control, and actions on objectives. Understanding the kill chain helps defenders identify opportunities to detect and disrupt attacks at each stage.
Question 3: Under Singapore's regulatory framework, which CSOC-related obligation do operators of Critical Information Infrastructure (CII) have under the Cybersecurity Act?
- CII owners must comply with mandatory cybersecurity standards and audits, and are required to report prescribed cybersecurity incidents to CSA (Correct answer)
- CII owners are exempt from cybersecurity obligations because they operate critical infrastructure
- CII owners may self-assess their cybersecurity posture without external oversight
- CII owners must operate a 24/7 CSOC with at least 50 staff as a minimum requirement
Correct answer: CII owners must comply with mandatory cybersecurity standards and audits, and are required to report prescribed cybersecurity incidents to CSA
Under the Cybersecurity Act, CII owners face enhanced obligations including mandatory compliance with codes of practice, regular cybersecurity audits, incident reporting requirements, and participation in cybersecurity exercises as directed by CSA.
Question 4: What is 'threat modelling' and how is it used in security operations planning?
- A structured process for identifying potential threats, attack vectors, and adversaries relevant to a specific system or organisation to inform defensive priorities (Correct answer)
- A statistical model used to predict the financial cost of future cyber attacks
- The process of modelling network topology to identify the optimal placement of security controls
- A regulatory requirement for organisations to document all known threats to their systems annually
Correct answer: A structured process for identifying potential threats, attack vectors, and adversaries relevant to a specific system or organisation to inform defensive priorities
Threat modelling systematically identifies who might attack a system, what they want to achieve, how they might do it, and what the impact would be. This informs the prioritisation of security controls and monitoring activities to address the most relevant threats.
Question 5: What is the purpose of tabletop exercises in a CSOC environment?
- To simulate cybersecurity incidents in a discussion-based format, testing and improving the team's response plans, decisions, and coordination without impacting real systems (Correct answer)
- To physically test whether the CSOC facility can withstand a physical security breach
- To evaluate the performance of security tools under simulated high-traffic conditions
- To train new analysts on basic CSOC procedures through a series of practical assignments
Correct answer: To simulate cybersecurity incidents in a discussion-based format, testing and improving the team's response plans, decisions, and coordination without impacting real systems
Tabletop exercises are scenario-based discussions where participants walk through their response to a simulated incident. They test decision-making, expose gaps in plans and communication, and improve coordination without the risk of impacting real systems.
Question 6: What is 'defence in depth' in cybersecurity operations?
- A security strategy that uses multiple, layered security controls so that if one fails, others remain to protect the system (Correct answer)
- A military-inspired concept where the most sensitive systems are kept in the deepest part of the network
- A strategy focusing all security resources on defending the most critical systems only
- A technique for conducting deep forensic analysis of compromised systems after a breach
Correct answer: A security strategy that uses multiple, layered security controls so that if one fails, others remain to protect the system
Defence in depth applies multiple security controls at different layers — network, host, application, and data — so that an attacker who bypasses one control still faces additional barriers. It eliminates single points of failure in a security architecture.
What is 'Security Orchestration, Automation, and Response' (SOAR) in CSOC operations?