CSX Security Operations Center (SOC) Operations 1 — Questions and Answers
Question 1: What is the primary function of a Security Operations Center (SOC)?
- Developing new software applications
- Continuously monitoring and analyzing an organization's security posture (Correct answer)
- Managing human resources and employee onboarding
- Performing financial audits and compliance reviews
Correct answer: Continuously monitoring and analyzing an organization's security posture
A SOC's primary function is to continuously monitor, detect, analyze, and respond to cybersecurity threats and incidents around the clock.
Question 2: Which tier in a typical three-tier SOC structure is responsible for initial alert triage?
- Tier 3 (advanced threat hunters)
- Tier 2 (incident responders)
- Tier 1 (alert analysts) (Correct answer)
- Tier 0 (automation layer)
Correct answer: Tier 1 (alert analysts)
Tier 1 analysts handle the first line of monitoring and triage incoming alerts to determine severity before escalating to higher tiers.
Question 3: What is a 'false positive' in the context of SOC alert management?
- A confirmed security incident that was successfully remediated
- An alert triggered by legitimate activity that is mistakenly identified as malicious (Correct answer)
- A critical vulnerability that has not yet been patched
- A successful red team penetration test finding
Correct answer: An alert triggered by legitimate activity that is mistakenly identified as malicious
A false positive occurs when a security tool flags benign or legitimate activity as a threat, requiring analyst time to investigate and dismiss.
Question 4: Which metrics are most commonly used to measure SOC effectiveness in detecting and resolving incidents?
- Number of tools deployed and total log volume ingested
- Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) (Correct answer)
- Total number of employees in the SOC and annual training hours
- Cost per security tool license and vendor renewal dates
Correct answer: Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
MTTD and MTTR are key performance indicators measuring how quickly threats are identified and how rapidly they are contained or resolved.
Question 5: What is the purpose of a threat intelligence feed in SOC operations?
- To track employee productivity and workstation activity
- To provide current information about known threats, IoCs, and attacker TTPs (Correct answer)
- To generate financial reports on security spending and ROI
- To manage software license renewals and vendor contracts
Correct answer: To provide current information about known threats, IoCs, and attacker TTPs
Threat intelligence feeds supply analysts with up-to-date indicators of compromise and adversary tactics to improve proactive detection capabilities.
Question 6: What is 'alert fatigue' in a SOC environment?
- When security monitoring tools stop generating alerts due to configuration errors
- When analysts become desensitized to alerts due to excessive volume, increasing the risk of missing real threats (Correct answer)
- When network bandwidth is overwhelmed by traffic from monitoring agents
- When a SIEM license expires and alerting functionality is disabled
Correct answer: When analysts become desensitized to alerts due to excessive volume, increasing the risk of missing real threats
Alert fatigue occurs when the sheer volume of alerts causes analysts to lose focus, raising the likelihood that genuine incidents are overlooked.
Question 7: Which SOC staffing model involves outsourcing security monitoring to a third-party provider?
- Dedicated internal SOC
- Managed Security Service Provider (MSSP) (Correct answer)
- Virtual SOC with part-time staff
- Co-managed hybrid SOC
Correct answer: Managed Security Service Provider (MSSP)
An MSSP is an external vendor that provides outsourced SOC services, including 24/7 monitoring, alerting, and incident response support.
What is the primary function of a Security Operations Center (SOC)?