>_ CyberQuiz
← All rooms
🛰️

SOC Level 1

Security Operations Center fundamentals: SIEM, log analysis, alert triage and threat intel.

Medium 50 questions · 755 pts Room score: 0/755
Q1 Easy 10 pts

What does SIEM stand for?

Q2 Easy 10 pts

An alert that fires on activity that is actually benign is a:

Q3 Medium 15 pts

A real attack that goes UNDETECTED is a:

Q4 Medium 15 pts

SOC analysts map attacker behavior to the MITRE ____ framework of tactics & techniques.

Q5 Medium 15 pts

Windows Event ID 4625 indicates:

Q6 Easy 10 pts

Windows Event ID 4624 indicates:

Q7 Medium 15 pts

The documented record of who handled evidence and when is the chain of ____ .

Q8 Easy 10 pts

EDR stands for:

Q9 Medium 15 pts

SOAR platforms primarily provide:

Q10 Medium 15 pts

An IDS differs from an IPS in that an IDS:

Q11 Easy 10 pts

An IOC (Indicator of Compromise) is:

Q12 Hard 20 pts

On the Pyramid of Pain, which indicator is HARDEST for attackers to change?

Q13 Medium 20 pts

Regular, fixed-interval callbacks from a host to an external server suggest:

Q14 Medium 15 pts

The FIRST action when triaging a new alert is usually to:

Q15 Medium 15 pts

SPF, DKIM and DMARC are used to combat:

Q16 Hard 20 pts

The security tool language for writing pattern-matching malware rules by content is ____ .

Q17 Hard 20 pts

Sigma rules are:

Q18 Medium 15 pts

Suricata and Snort are examples of:

Q19 Medium 15 pts

MTTD in SOC metrics means:

Q20 Medium 15 pts

MTTR typically means:

Q21 Easy 10 pts

A SOC 'playbook' is:

Q22 Medium 15 pts

The typical incident-response lifecycle (NIST) begins with:

Q23 Medium 15 pts

'Containment' in incident response aims to:

Q24 Medium 15 pts

Alert fatigue is a risk because:

Q25 Medium 20 pts

UEBA detects threats by:

Q26 Hard 20 pts

Sysmon is used to:

Q27 Medium 15 pts

A sudden spike in outbound data to an unknown host may indicate:

Q28 Medium 15 pts

DLP tools are designed to:

Q29 Medium 15 pts

Many repeated failed logons followed by a success suggests:

Q30 Medium 20 pts

Threat hunting is best described as:

Q31 Medium 15 pts

The model describing attack stages from recon to actions-on-objectives is the Cyber Kill ____ .

Q32 Medium 15 pts

Log timestamps across systems should be normalized to:

Q33 Medium 15 pts

'Enrichment' of an alert means:

Q34 Medium 15 pts

A honeypot is:

Q35 Medium 15 pts

CVSS is used to:

Q36 Hard 20 pts

Which log source best shows PROCESS creation on Windows?

Q37 Hard 20 pts

NetFlow data provides:

Q38 Medium 15 pts

A PCAP file contains:

Q39 Hard 20 pts

First responder rule: preserve evidence by:

Q40 Medium 15 pts

A correlation rule in a SIEM:

Q41 Easy 10 pts

Tiered SOC roles: which handles initial alert triage?

Q42 Easy 10 pts

Escalation to Tier 2/3 is appropriate when:

Q43 Medium 15 pts

Ransomware activity often shows:

Q44 Medium 15 pts

Analyzing a suspicious email, you inspect the:

Q45 Medium 15 pts

A detection 'use case' is:

Q46 Medium 15 pts

Baselining is important because anomalies are defined relative to:

Q47 Medium 15 pts

Log RETENTION policy matters because:

Q48 Easy 10 pts

A 'true positive' alert means:

Q49 Medium 15 pts

Threat intelligence 'TTPs' stands for:

Q50 Medium 15 pts

The best outcome of a post-incident review is: