
EC-CouncilCertified SOC Analyst
Domain 1Objective 1
Security Operations Center (SOC) Fundamentals CSA Practice Questions (Page 5)
Part of the Security Operations and Management domain, which makes up ~12% of our current practice bank.
45questions here
9free pages
8concepts
Questions 21–25
- 21
Which SOC maturity model stage is characterized by ad-hoc processes and minimal formal documentation?
Select an answer first - 22
A global enterprise operates a SOC that follows the sun model, with teams in three geographic regions. A security incident occurs in the Asia-Pacific region during the local team's shift. According to the follow-the-sun model, what should happen when the Asia-Pacific shift ends?
Select an answer first - 23
What does a high false positive rate in a SOC indicate?
Select an answer first - 24
During a major security incident, a SOC analyst discovers that the incident response plan does not cover the specific type of attack that occurred. The analyst is unsure who has the authority to make decisions outside the existing plan. Which role in the SOC is typically responsible for making such decisions during an incident?
Select an answer first - 25
A SOC analyst is reviewing a high-priority alert that was generated by the SIEM. The alert indicates a potential data exfiltration from a database server. According to the SOC's procedures, what should the analyst do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.