Q1
Easy
10 pts
SOC Level 1
Security Operations Center fundamentals: SIEM, log analysis, alert triage and threat intel.
Q2
Easy
10 pts
An alert that fires on activity that is actually benign is a:
Q3
Medium
15 pts
A real attack that goes UNDETECTED is a:
Q4
Medium
15 pts
SOC analysts map attacker behavior to the MITRE ____ framework of tactics & techniques.
Q5
Medium
15 pts
Windows Event ID 4625 indicates:
Q6
Easy
10 pts
Windows Event ID 4624 indicates:
Q7
Medium
15 pts
The documented record of who handled evidence and when is the chain of ____ .
Q8
Easy
10 pts
EDR stands for:
Q9
Medium
15 pts
SOAR platforms primarily provide:
Q10
Medium
15 pts
An IDS differs from an IPS in that an IDS:
Q11
Easy
10 pts
An IOC (Indicator of Compromise) is:
Q12
Hard
20 pts
On the Pyramid of Pain, which indicator is HARDEST for attackers to change?
Q13
Medium
20 pts
Regular, fixed-interval callbacks from a host to an external server suggest:
Q14
Medium
15 pts
The FIRST action when triaging a new alert is usually to:
Q15
Medium
15 pts
SPF, DKIM and DMARC are used to combat:
Q16
Hard
20 pts
The security tool language for writing pattern-matching malware rules by content is ____ .
Q17
Hard
20 pts
Sigma rules are:
Q18
Medium
15 pts
Suricata and Snort are examples of:
Q19
Medium
15 pts
MTTD in SOC metrics means:
Q20
Medium
15 pts
MTTR typically means:
Q21
Easy
10 pts
A SOC 'playbook' is:
Q22
Medium
15 pts
The typical incident-response lifecycle (NIST) begins with:
Q23
Medium
15 pts
'Containment' in incident response aims to:
Q24
Medium
15 pts
Alert fatigue is a risk because:
Q25
Medium
20 pts
UEBA detects threats by:
Q26
Hard
20 pts
Sysmon is used to:
Q27
Medium
15 pts
A sudden spike in outbound data to an unknown host may indicate:
Q28
Medium
15 pts
DLP tools are designed to:
Q29
Medium
15 pts
Many repeated failed logons followed by a success suggests:
Q30
Medium
20 pts
Threat hunting is best described as:
Q31
Medium
15 pts
The model describing attack stages from recon to actions-on-objectives is the Cyber Kill ____ .
Q32
Medium
15 pts
Log timestamps across systems should be normalized to:
Q33
Medium
15 pts
'Enrichment' of an alert means:
Q34
Medium
15 pts
A honeypot is:
Q35
Medium
15 pts
CVSS is used to:
Q36
Hard
20 pts
Which log source best shows PROCESS creation on Windows?
Q37
Hard
20 pts
NetFlow data provides:
Q38
Medium
15 pts
A PCAP file contains:
Q39
Hard
20 pts
First responder rule: preserve evidence by:
Q40
Medium
15 pts
A correlation rule in a SIEM:
Q41
Easy
10 pts
Tiered SOC roles: which handles initial alert triage?
Q42
Easy
10 pts
Escalation to Tier 2/3 is appropriate when:
Q43
Medium
15 pts
Ransomware activity often shows:
Q44
Medium
15 pts
Analyzing a suspicious email, you inspect the:
Q45
Medium
15 pts
A detection 'use case' is:
Q46
Medium
15 pts
Baselining is important because anomalies are defined relative to:
Q47
Medium
15 pts
Log RETENTION policy matters because:
Q48
Easy
10 pts
A 'true positive' alert means:
Q49
Medium
15 pts
Threat intelligence 'TTPs' stands for:
Q50
Medium
15 pts