Security Monitoring & SIEM
Incident Response
Threat Detection
Network Security
SOC Fundamentals
100

What does SIEM stand for?

Security Information and Event Management

100

What is the first phase of the incident response lifecycle?

Preparation

100

What is malware that encrypts files and demands payment?

Ransomware

100

Which protocol securely encrypts web traffic?

HTTPS

100

What does SOC stand for?

Security Operations Center

200

What type of logs would you review to investigate a failed login attempt?

Authentication/Security logs

200

What does "containment" mean during an incident?

Limiting the spread or impact of the attack

200

What type of email attack attempts to steal credentials?

Phishing

200

Which port does HTTPS use by default?

443

200

What is the primary responsibility of a Tier 1 SOC analyst?

Monitoring alerts, performing initial triage, and escalating confirmed threats.

300

What process combines logs from multiple devices into one platform for analysis?

Log aggregation

300

Which team is responsible for coordinating technical actions during a cybersecurity incident?

Incident Response Team (IRT)

300

What does IOC stand for?

Indicator of Compromise

300

What device filters network traffic based on security rules?

Firewall

300

What is the difference between a true positive and a false positive alert?

A true positive is a legitimate security event, while a false positive is an alert that incorrectly indicates malicious activity.

400

What is the term for a rule that generates an alert when suspicious activity is detected?  

Correlation rule

400

What document records every action taken during an investigation?

Incident timeline (or investigation log)

400

What does TTP stand for in threat intelligence?

Tactics, Techniques, and Procedures

400

What system monitors network traffic for malicious activity and generates alerts?

IDS (Intrusion Detection System)

400

What document provides step-by-step instructions for investigating and responding to a specific type of security alert?

A playbook (or incident response playbook).

500

Name one common SIEM platform used in enterprise environments.

Splunk, Microsoft Sentinel, QRadar, ArcSight, Elastic SIEM

500

After eradication and recovery, what final phase helps improve future responses?

Lessons Learned (Post-Incident Review)

500

Which framework is commonly used to classify attacker behavior using TTPs?

MITRE ATT&CK

500

What technology allows secure encrypted communication over the internet for remote users?

VPN (Virtual Private Network)

500

What is the purpose of threat intelligence in a SOC?

To provide information about current and emerging threats that helps analysts detect, investigate, and respond to attacks more effectively.