Security Operations Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Operations flashcards as text
A SOC analyst notices repeated failed login attempts from the same IP address across multiple accounts within a 10-minute window. What type of attack is most likely occurring?
Answer: Password spraying
Password spraying uses a few common passwords against many accounts to avoid lockout thresholds, matching the pattern of multiple accounts targeted rapidly.
Which SIEM correlation rule would BEST detect lateral movement after an initial compromise?
Answer: Successful login from a new host to multiple internal systems in a short timeframe
Lateral movement involves an attacker using a foothold to authenticate across multiple internal systems, making cross-host successful logins the strongest indicator.
A threat analyst is reviewing NetFlow data and finds a host sending 50 MB of data to an external IP at 2 AM daily. What should be investigated first?
Answer: DNS query logs for the destination domain
DNS query logs reveal the domain behind the external IP, helping determine if traffic is C2 beaconing, DLP, or legitimate scheduled transfers.
During incident response, a host is confirmed to be infected with malware. Which action preserves the most forensic evidence before remediation?
Answer: Capture a full memory dump and disk image
Memory dumps capture volatile artifacts like running processes and injected code, while disk images preserve file system state for post-incident analysis.
Which metric BEST measures the efficiency of a SOC's incident detection capability?
Answer: Mean Time to Detect (MTTD)
MTTD measures how quickly the SOC identifies a threat after it occurs, directly reflecting detection capability effectiveness.
An analyst finds a PowerShell script executing from a user's temp directory that encodes commands in Base64. What is the PRIMARY concern?
Answer: Living-off-the-land attack using built-in tools to evade detection
Base64-encoded PowerShell executed from temp directories is a classic living-off-the-land technique that abuses trusted system tools to blend with normal activity.
A security team wants to proactively search for signs of compromise not yet detected by automated tools. What practice should they implement?
Answer: Threat hunting
Threat hunting is the proactive, human-driven search for attacker TTPs and indicators that automated detection systems have not yet flagged.