Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 1Objective 2

SOC Components, Workflow, and Metrics CSA Practice Questions (Page 5)

Part of the Security Operations and Management domain, which makes up ~12% of our current practice bank.

41questions here
9free pages
3concepts

Questions 21–25

  1. 21application · medium

    A SOC analyst receives an alert from the SIEM indicating a possible brute-force attack against a domain controller. The analyst checks the source IP against threat intelligence, sees it is a known scanning host, and then reviews the authentication logs. The analyst confirms that no accounts were compromised and closes the alert as a false positive. Which step of the SOC workflow does the analyst perform immediately after validating the alert as a true positive?

    Select an answer first
  2. 22application · medium

    A company is establishing a SOC and wants to ensure that alerts are properly investigated and escalated according to severity. The SOC manager assigns specific roles and responsibilities for triage, escalation, and incident response. Which SOC component is the manager primarily addressing?

    Select an answer first
  3. 23expert · hard

    A SOC is experiencing a high volume of alerts, many of which are false positives. The team is overwhelmed and MTTT has increased from 15 minutes to 2 hours. The manager wants to reduce alert fatigue without increasing the risk of missing true positives. Which combination of actions is most effective?

    Select an answer first
  4. 24application · medium

    A SOC analyst is reviewing the weekly metrics. The SOC received 1,000 alerts, and 100 were escalated as incidents. Of those escalated, 70 were confirmed as true positives. What is the false positive rate for the week?

    Select an answer first
  5. 25application · medium

    A SOC manager reviews the past month's metrics. The SOC received 1,200 alerts, of which 240 were escalated as true positives. The average time from alert creation to escalation was 45 minutes, and the average time from escalation to containment was 3 hours. Which metric should the manager calculate to evaluate the efficiency of the triage phase?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.