
EC-CouncilCertified SOC Analyst
Domain 1Objective 1
Security Operations Center (SOC) Fundamentals CSA Practice Questions (Page 2)
Part of the Security Operations and Management domain, which makes up ~12% of our current practice bank.
45questions here
9free pages
8concepts
Questions 6–10
- 6
A company is deciding between a fully in-house SOC and a fully outsourced SOC. The company has strict data residency requirements and wants to maintain complete control over its security data. Which model is the most appropriate?
Select an answer first - 7
A SOC analyst receives an alert from the SIEM about a suspicious outbound connection from a finance workstation to an unknown IP address. The alert lacks context about whether this is a known threat. According to standard SOC processes, what should the analyst do FIRST?
Select an answer first - 8
During a major security incident, a SOC analyst discovers that the incident response plan is outdated and does not cover the type of attack that occurred. According to SOC best practices, what should the analyst do?
Select an answer first - 9
Which tool is commonly used in a SOC to automate repetitive tasks and orchestrate response actions?
Select an answer first - 10
A SOC manager is evaluating their team's maturity using a SOC maturity model. The team currently has documented processes, a SIEM, and a formal incident response plan, but they do not proactively hunt for threats. According to common maturity models, which stage best describes this SOC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.