01. A correlation rule is written so that it raises one alert when the same account produces repeated failed logon events inside a defined time window.
Which type of correlation rule is this?
a) A threshold rule, which fires when the SIEM sees a chosen event more than a set number of times inside a window
b) A statistical rule, which fires when activity departs from a learned baseline
c) A parsing rule, which splits each record the SIEM receives into named fields
d) A sequence rule, which fires when the chosen events arrive in the order the author specified
02. A SOC already runs EDR on its hosts and now wants the same style of behavioral detection and response applied to the traffic on its network.
Which technology does that?
a) Security information and event management (SIEM), which correlates the logs those devices write
b) A cloud access security broker (CASB)
c) Network detection and response (NDR), which analyzes traffic for suspicious behavior and supports action against what it finds
d) A threat intelligence platform (TIP), which collects and enriches indicators from outside the organization
03. A SOC records the outcome of every detection so that the accuracy of its rules can be judged.
Which outcome is a true positive?
a) Suspicious activity an analyst investigated without reaching a conclusion
b) Benign activity that raised an alert and consumed analyst time
c) Benign activity that the detection logic correctly left unalerted
d) Malicious activity that correctly raised an alert
04. A Tier 1 analyst has validated an alert and gathered the context around it.
Which circumstance means the alert should be escalated rather than finished at Tier 1?
a) The alert is one of several, all from the same detection rule, raised during the shift
b) The alert's severity was set by the rule rather than by an analyst
c) The alert involves a critical asset or a confirmed compromise, or acting on it needs an authority the analyst does not hold (approval to take a server offline)
d) The alert came from a rule that is still being tested or tuned in the environment
05. A vulnerability scanner's weekly sweep matches the SOC's port-scan detection every time it runs. The team decides that the scanner's own traffic should stop raising that alert.
What does good practice require alongside the exclusion itself?
a) A message to the scanning team asking them to run the sweep less often
b) A copy of the scanner's configuration, attached to the correlation rule, so that later analysts can see what it scans
c) An increase in the rule's threshold or window until the scanner's sweep no longer reaches it
d) A recorded justification naming the source, the reason and the owner, so the exception can be reviewed later
06. An analyst wants a detection that fires only when a burst of failed logons for one account is followed by a successful logon, and then by the creation of a new administrative account.
Which type of correlation rule expresses that requirement?
a) A signature rule, because each event matches a known pattern
b) A threshold rule, because the detection depends on how many times each of the three events is observed
c) A sequence rule, because the detection depends on the three events arriving in a stated order
d) An anomaly rule, because each event departs from the baseline for that account
07. An organization wants its own access and usage policy applied to the cloud services its staff sign in to, even though it does not operate those services.
Which technology is built to sit in that position?
a) A network firewall, which permits or blocks connections by address and port
b) An endpoint agent installed on each device that reaches those services
c) The correlation engine, which evaluates arriving events against the rules
d) A cloud access security broker (CASB)
08. Ransomware has encrypted file servers across a company's corporate network and taken its mail system down. The SOC's monitoring platform, its case system and its communications are all unaffected, and the team works the incident through them.
Which property of the SOC's own infrastructure made that possible?
a) Its logs are retained long enough for the team to reconstruct the attack afterwards
b) It is built with its own redundancy and kept separate from the environment it monitors
c) Its platform runs on the same corporate domain and mail system, so the team already held the access the incident demanded
d) Its correlation rules covered the ransomware behavior
09. Which technology builds a baseline of normal behavior for users and devices, then reports activity that departs from it?
a) User and entity behavior analytics (UEBA)
b) A threat intelligence platform (TIP), which aggregates and enriches external feeds
c) A security orchestration and automated response (SOAR) platform
d) A ticketing system tracking each case to closure
10. Which technology in a SOC's tool set is built to identify sensitive data and stop it leaving the organization?
a) A threat intelligence platform (TIP), which gathers indicators of attacker activity from outside
b) Data loss prevention (DLP), which inspects content and blocks its transfer
c) A network firewall controlling which connections are permitted
d) A web proxy filtering which sites staff may reach