Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 1Objective 2

SOC Components, Workflow, and Metrics CSA Practice Questions (Page 6)

Part of the Security Operations and Management domain, which makes up ~12% of our current practice bank.

41questions here
9free pages
3concepts

Questions 26–30

  1. 26foundation · easy

    A SOC received 200 alerts in one week. Of these, 40 were investigated and confirmed as actual incidents. What is the false positive rate for that week?

    Select an answer first
  2. 27application · medium

    A SOC manager wants to measure the team's ability to respond to incidents. The team recorded the following times for an incident: detection at 09:00, containment at 09:20, and resolution at 10:00. What is the Mean Time to Contain (MTTC) for this incident?

    Select an answer first
  3. 28foundation · easy

    Which SOC metric measures the time elapsed from when an incident occurs to when it is first detected?

    Select an answer first
  4. 29application · medium

    During a security incident, a SOC analyst has identified a compromised host and isolated it from the network. According to the SOC workflow, what should the analyst do next?

    Select an answer first
  5. 30application · medium

    A SOC manager wants to measure the team's effectiveness in containing security incidents after they have been detected. Which metric should be tracked?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.