What does SIEM stand for?
Security Information and Event Management
What is the first phase of the incident response lifecycle?
Preparation
What is malware that encrypts files and demands payment?
Ransomware
Which protocol securely encrypts web traffic?
HTTPS
What does SOC stand for?
Security Operations Center
What type of logs would you review to investigate a failed login attempt?
Authentication/Security logs
What does "containment" mean during an incident?
Limiting the spread or impact of the attack
What type of email attack attempts to steal credentials?
Phishing
Which port does HTTPS use by default?
443
What is the primary responsibility of a Tier 1 SOC analyst?
Monitoring alerts, performing initial triage, and escalating confirmed threats.
What process combines logs from multiple devices into one platform for analysis?
Log aggregation
Which team is responsible for coordinating technical actions during a cybersecurity incident?
Incident Response Team (IRT)
What does IOC stand for?
Indicator of Compromise
What device filters network traffic based on security rules?
Firewall
What is the difference between a true positive and a false positive alert?
A true positive is a legitimate security event, while a false positive is an alert that incorrectly indicates malicious activity.
What is the term for a rule that generates an alert when suspicious activity is detected?
Correlation rule
What document records every action taken during an investigation?
Incident timeline (or investigation log)
What does TTP stand for in threat intelligence?
Tactics, Techniques, and Procedures
What system monitors network traffic for malicious activity and generates alerts?
IDS (Intrusion Detection System)
What document provides step-by-step instructions for investigating and responding to a specific type of security alert?
A playbook (or incident response playbook).
Name one common SIEM platform used in enterprise environments.
Splunk, Microsoft Sentinel, QRadar, ArcSight, Elastic SIEM
After eradication and recovery, what final phase helps improve future responses?
Lessons Learned (Post-Incident Review)
Which framework is commonly used to classify attacker behavior using TTPs?
MITRE ATT&CK
What technology allows secure encrypted communication over the internet for remote users?
VPN (Virtual Private Network)
What is the purpose of threat intelligence in a SOC?
To provide information about current and emerging threats that helps analysts detect, investigate, and respond to attacks more effectively.