
EC-CouncilCertified SOC Analyst
Domain 1Objective 2
SOC Components, Workflow, and Metrics CSA Practice Questions (Page 6)
Part of the Security Operations and Management domain, which makes up ~12% of our current practice bank.
41questions here
9free pages
3concepts
Questions 26–30
- 26
A SOC received 200 alerts in one week. Of these, 40 were investigated and confirmed as actual incidents. What is the false positive rate for that week?
Select an answer first - 27
A SOC manager wants to measure the team's ability to respond to incidents. The team recorded the following times for an incident: detection at 09:00, containment at 09:20, and resolution at 10:00. What is the Mean Time to Contain (MTTC) for this incident?
Select an answer first - 28
Which SOC metric measures the time elapsed from when an incident occurs to when it is first detected?
Select an answer first - 29
During a security incident, a SOC analyst has identified a compromised host and isolated it from the network. According to the SOC workflow, what should the analyst do next?
Select an answer first - 30
A SOC manager wants to measure the team's effectiveness in containing security incidents after they have been detected. Which metric should be tracked?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.