Browse all practice questions for the Security Operations Exam 3 Practice. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Security Operations Exam 3 Practice course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Define the principle of least privilege and describe how it should be implemented in IAM.
  • What is data loss prevention (DLP) and where should DLP be deployed to be effective?
  • Which cloud deployment model is shared by organizations with common interests and compliance requirements?
  • Which process helps identify the fundamental reason an incident occurred to prevent recurrence?
  • How does a Content Delivery Network (CDN) help mitigate DoS/DDoS attacks?
  • Which intrusion model describes seven phases: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, C2, and Actions on Objectives?
  • Which three metrics describe SOC efficiency: MTTD, MTTR, MTTRem?
  • What term describes algorithms that learn patterns from data and are used for supervised malware detection and UEBA?
  • Which term describes a network composed of multiple decoy systems designed to attract attackers?
  • In incident response, choose the correct description of malware analysis levels.
  • Which statement best describes MITRE ATT&CK mapping in practice?
  • Which local configuration file can be poisoned to redirect domain name resolution to attacker-controlled hosts?
  • Differentiate patch management from vulnerability scanning and explain how they work together.
  • Which technologies help identify unauthorized devices on a network?
  • Which Windows Registry root key includes subkeys that define settings for all users on the computer?
  • In the seven-phase intrusion model, which phase follows Installation?
  • Which term best describes a security model that requires continuous verification of identity and least-privilege access?
  • Which term describes unauthorized employee use of AI tools that risks data leakage into public models and compliance violations without IT governance?
  • Which sequence lists the core stages of digital forensics: Identification, Collection, Analysis, Reporting, Imaging, and File Carving?
  • Which access control model assigns permissions based on the user's role within an organization?
  • Which category of tools includes GDB and WinDbg used for stepping through code, memory inspection, and setting breakpoints during vulnerability analysis?
  • What role do tabletop exercises serve in validating IR capabilities, and what outputs should they produce?
  • Which term best describes using automated analytics, NLP, and predictive capabilities to accelerate threat detection and SOC tasks?
  • Which volatile data sources should be collected during an in-progress incident?
  • Which statement correctly distinguishes Static (SAST) and Dynamic (DAST) analysis of vulnerabilities?
  • What is a common mitigation for legacy systems lacking patches?
  • Which practice best describes session management protection?
  • In the threat intelligence lifecycle, which stage is responsible for turning collected data into detections and risk assessments?
  • Which phase of the incident response lifecycle focuses on post-incident analysis and improvements?
  • Name three stages of malware analysis at a high level and the objective of each.
  • Tabletop exercises are designed to test what aspect?
  • Which of the following describes a primary purpose of a CASB?
  • An executive summary in incident response typically includes which elements?
  • What does UEBA primarily analyze?
  • What is a documented risk associated with using large language models in security operations?
  • In the Windows Registry, which root key stores machine-wide settings for all users?
  • Which of the following best describes a typical risk mitigated by change management in security operations?
  • Which statement best describes the purpose of logging and monitoring in cloud environments?
  • What term describes the process of identifying, collecting, and producing electronically stored information for legal proceedings, including legal holds?
  • How can phishing simulations be used to improve SOC readiness?
  • Which framework provides a widely adopted risk management approach for cybersecurity, and what are its five core functions?
  • What is coordinated disclosure in vulnerability management, and what are its benefits and risks?
  • Credential Stuffing uses leaked credentials from breaches to test across multiple accounts. Which term describes this attack type?
  • Which XML attack exploits external entities to read files or perform Denial of Service via XML Bombs?
  • Which technique involves repeatedly asking 'Why' to uncover root causes?
  • Dynamic DNS can be abused by attackers to provide what capability for command-and-control (C2) communications?
  • What is the term for intercepting or altering communications between two parties using ARP spoofing or rogue APs?
  • In zero trust security, which principle governs access requests?
  • Which statement best explains why CVSS alone is not sufficient for prioritizing vulnerabilities?
  • Which technology enables machines to understand human language and is used in phishing detection and threat text analysis?
  • Which cookies settings help protect session data?
  • Which of the following statements best describes an Indicator of Compromise (IOC)?
  • Which groups are considered stakeholders requiring tailored communication strategies during incident response?
  • Which term refers to the sum of exposed points that attackers can target, including passive and active reconnaissance techniques?
  • Which of the following correctly defines MTTD, MTTR, and MTTC and their relationship?
  • What is the documented, tamper-proof record that tracks evidence handling from collection to court to prove integrity and authenticity?
  • Which technique is used to detect Command-and-Control (C2) traffic by examining network behavior such as beaconing, unusual DNS queries, connections to new domains, or anomalous User-Agents?
  • In incident response, what best describes containment?
  • What term describes a unified management console that aggregates data from multiple security tools into a single interface to improve situational awareness?
  • What term describes a network of decoy systems used to lure and trap attackers?
  • Generative AI in security contexts can be used for which of the following?
  • In incident response, which action is used to remove the root cause of an incident?
  • Which technique is commonly used to move laterally by executing commands on remote systems?
  • MFA mitigates which attack that targets many accounts with a few commonly used passwords?
  • Which impact category describes an incident that affects the entire organization?
  • Which platforms coordinate and automate security tasks across multiple tools and processes?
  • What is zero-trust architecture and what are its core components relevant to operations?
  • Indicators of Compromise (IOCs) are commonly derived from which sources?
  • Which element best describes hash verification in evidence handling for digital forensics?
  • Which signal most strongly justifies declaring an incident rather than treating it as a single alert?
  • Which concept pair describes the difference between SIEM and SOAR in security operations?
  • Which vulnerability allows an attacker to access files outside the web root by using path traversal sequences such as '../'?
  • What does CVE stand for in publicly disclosed cybersecurity vulnerabilities?
  • Which KPI measures the time from threat detection to remediation?
  • What is the purpose of incident response playbooks, and how do they differ from tabletop exercises?
  • Which tool is a command-line network scanner for host discovery, port scanning, and version detection?
  • In an incident response plan, which component includes tools such as SIEMs, IDS, vulnerability scanners, and netflow analyzers?
  • What term describes an advanced form of AI capable of autonomously planning and executing tasks with minimal human input?
  • Which vulnerability involves injecting malicious scripts into trusted websites, with types Reflected, Stored, and DOM-based, mitigated by output encoding and Content Security Policy?
  • Which item is a common focus of auditing system accounts?
  • Which security model emphasizes strict identity verification and microsegmentation regardless of network location?
  • Why is time synchronization important for log analysis, and what protocols support it?
  • Which technique ensures SQL queries treat user input strictly as data, preventing injection?
  • Which metric groups are used in the CVSS scoring framework?
  • What is a 'kill chain' model, and how does it guide incident response actions?
  • Which term refers to a subset of machine learning that uses multi-layered neural networks to model complex patterns and is commonly applied in malware and phishing detection?
  • Which statement best defines residual risk?
  • Which groups are stakeholders requiring tailored communication during incident response?
  • Which tool captures live network traffic for analysis and can be used defensively for troubleshooting and offensively for credential harvesting?
  • Which component enables software communication but is also a common attack vector that requires strong authentication, input validation, and rate limiting?
  • Which scoring framework uses a 0-10 scale and a Vector String encoding Base, Temporal, and Environmental metric groups?
  • Which practice involves reviewing user accounts for dormant status, excessive privileges, default credentials, orphaned accounts, non-expiring passwords, shared accounts, and irregular login times?
  • What are the three primary Security Control Categories?
  • Which Security Control Objective describes actions taken during an incident?
  • Which term refers to publicly disclosed cybersecurity vulnerabilities with a standard dictionary for identification?
  • In incident response planning, which element defines the step-by-step actions to be taken during an incident?
  • What is the purpose of threat modeling in the secure software development lifecycle (SSDLC)?
  • What are staging areas in the context of data exfiltration?
  • Which Unix tool can monitor real-time resource usage to detect anomalies such as cryptojacking?
  • Local File Inclusion (LFI) and Remote File Inclusion (RFI) vulnerabilities are prevented by which measures?
  • Which security testing technique involves feeding malformed data to software to cause crashes and reveal vulnerabilities?
  • What best describes threat feeds in cybersecurity intelligence?
  • In reconnaissance, which activity is considered passive, mapping information without actively probing systems?
  • How does proactive threat hunting differ from traditional detection, and what methodologies are used?
  • Which term describes automated tools that crawl web applications and inject payloads to discover vulnerabilities such as XSS and SQLi?
  • Authorized simulated attack to identify vulnerabilities by chaining weaknesses to demonstrate real risk.
  • Which vulnerability occurs when session tokens or login mechanisms are flawed, enabling attackers to impersonate users (for example, due to weak passwords or lack of MFA)?
  • Which category encompasses threats such as XXE and XML Bombs targeting XML parsers?
  • What term specifically refers to a single decoy system used to trap attackers?
  • Spotting compromises via unusual outbound connections, privilege escalation, or abnormal process ancestry falls under which activity?
  • SCAP uses baselines such as STIGs to check configurations. Which baseline is specifically used for secure configuration compliance?
  • Threat hunting is best described as what?
  • Which access control models are commonly used to implement least-privilege in IAM?
  • To ensure accurate time for incident response, which time synchronization method is recommended?
  • What type of attack forces a server to make requests to internal or unintended resources, potentially exposing cloud metadata or internal databases?
  • What is the term for applying updates to fix vulnerabilities, usually scheduled during maintenance windows?
  • What is the primary function of Endpoint Detection and Response (EDR)?
  • To detect data exfiltration over non-standard channels, which indicator is most relevant?
  • What is log normalization, why is it necessary for SIEM, and what challenges can arise?
  • Which data type is an example of Protected Health Information (PHI) under HIPAA?
  • What constitutes an evidence chain of custody in digital forensics, and why is it critical for admissibility?
  • Which technique helps prevent injection attacks by ensuring inputs are safe and well-formed before processing?
  • What is a CASB and what functions does it provide?
  • How does EDR complement traditional antivirus?
  • Which compliance standards commonly mandate automated vulnerability identification tools like scanners?
  • Which tools evaluate cloud configurations for misconfigurations and align with frameworks like CIS Benchmarks (examples include ScoutSuite and Prowler)?
  • Which phase of the incident response lifecycle focuses on establishing the IR team, playbooks, and resources?
  • How do backup strategies relate to recovery time objectives (RTO) and recovery point objectives (RPO) in DR planning?
  • What term describes predefined, step-by-step procedures that security orchestration platforms execute automatically to reduce MTTR?
  • Which discovery approach relies on passively monitoring traffic to identify devices and connections?
  • Which threat modeling frameworks are given as examples in the threat modeling process?
  • What security service sits between cloud consumers and cloud providers to enforce security policies, provide visibility, DLP, and shadow IT detection?
  • Which cloud deployment model is a mix of public and private environments?
  • Which tool provides a GUI-based network protocol analyzer for capturing and analyzing raw frames?
  • What are the stages of threat intelligence lifecycle and how should it be integrated into security operations?
  • Which term describes aggregating logs from all devices into a single repository to enable cross-environment correlation and forensic evidence?
  • Probing target systems to discover open TCP/UDP ports using techniques like SYN stealth; basis for service fingerprinting.
  • Industrial Control Systems (ICS) present unique challenges such as real-time requirements and safety implications. Which statement best captures this?
  • Which are components of the SCAP standard?
  • What is the difference between log correlation and alert correlation in SIEM, and why are both important?
  • Which framework comprises Preparation, Detection & Analysis, Containment/Eradication/Recovery, and Post-Incident Activity?
  • Credentialed scans differ from non-credentialed scans in that credentialed scans:
  • What term describes a connection initiated from a compromised host back to the attacker, bypassing inbound firewall rules?
  • Which Unix command monitors CPU usage in real time to help detect issues like cryptojacking?
  • What is the defenders' primary objective in the seven-phase intrusion model?
  • What are common Initial Access techniques in MITRE ATT&CK, and how can detections be built around them?
  • What is the role of business continuity planning (BCP) in security operations and how does it relate to disaster recovery?
  • Which approach reduces the attack surface by applying secure configuration baselines (for example CIS benchmarks) through centralized management tools like GPOs or scripts?
  • Which statement best describes a SOC playbook as compared to a digital forensics procedure?
  • Which open-source penetration testing platform provides exploit modules and payloads (e.g., Meterpreter) for attack simulation?
  • Which term refers to attacks involving psychological manipulation to trick users, including phishing, vishing, baiting, and tailgating?
  • What security paradigm is described by the phrase 'Never trust, always verify' and emphasizes identity validation and microsegmentation?
  • Which flaw types are commonly discovered by web application vulnerability scanners such as Burp Suite?
  • Which XML-related threat category includes attacks like XML Bombs used to overwhelm parsers?
  • Compare RBAC and ABAC; what are the security implications of each approach?
  • Which mechanism assigns trust scores to domains or IPs to indicate malicious or benign status?
  • Which of the following best describes an RBAC access control model?
  • How does a CASB integrate with an IdP and what benefits does SSO bring to security operations?
  • ATLAS Frameworks extend threat modeling to adversarial threats against which type of systems?
  • In zero-trust, what constitutes 'continuous authorization'?
  • Which item is not typically listed as a core incident response plan component?
  • Which term describes the ongoing process of checking systems for known vulnerabilities to satisfy regulatory compliance?
  • Which set of tools includes Strings, whois, VirusTotal, hashing, and hex editors?
  • Which type of attacks are mitigated by parameterized queries and safe coding practices?
  • What is data classification, and how does it inform incident response prioritization and access controls?
  • What ongoing capability does EDR provide to improve detection beyond automated alerts?
  • Which capability is provided by a CASB?
  • In digital forensics, which process creates a bit-for-bit copy of storage media to preserve evidence?
  • In the MITRE ATT&CK framework, what does the acronym TTP stand for?
  • SCAP is a suite of standards enabling automated vulnerability management and compliance checking against baselines like STIGs. What does SCAP stand for?
  • What is the primary function of a firewall in a layered security architecture?
  • Which testing approach represents a realistic end-to-end drill that may involve red teams?
  • What is UEBA and how does it improve detection of insider threats?
  • Which statement about the role of encryption in cloud security is accurate?
  • Which of the following is the strongest indicator of exfiltration over non-standard channels?
  • Which statement accurately describes virtualization components—Hypervisors, Application Virtualization, and Containers?
  • Which description best captures the common character of scan types in security assessments?
  • In threat detection metrics, which term describes a benign item that is incorrectly flagged as malicious?
  • Which concealment techniques are used for hiding data exfiltration?
  • Which Windows command-line tool is the counterpart to tcpdump for packet capture?
  • Which mitigation is commonly used to defend against Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks?
  • What technique involves running untrusted code in an isolated environment to observe behavior safely?
  • What is the primary purpose of change management in security operations, and what risks does it mitigate?
  • Which Windows feature is commonly abused by attackers for persistence?
  • Which attack types are commonly targeted by automated web vulnerability scanners?
  • Which model is a phased cyberattack framework used to identify defender's opportunities to disrupt an attack?
  • Explain the importance of chain of custody during digital forensics investigations and what can happen if it's broken.
  • Which term describes periodic outbound communication from compromised hosts to a command-and-control server to evade detection?
  • Deconstructing software or hardware without source code to understand its function or find flaws.
  • Which category best describes Burp Suite and Qualys Web Application Scanning as tools?
  • What are the core components of a digital forensics procedure?
  • Which sequence correctly describes incident response stages?
  • Which threat actor type is most associated with financial gain or ransomware?
  • Unauthorized changes such as new autorun keys or modified system binaries are indicators of malware persistence in which data areas?
  • Which statement best describes the purpose of an incident response runbook and its essential elements?
  • What is the purpose of a Legal Hold in incident response?
  • Define log retention policy and its importance for forensics and compliance.
  • How does MITRE ATT&CK mapping assist SOC analysts in detection and response activities?
  • What is a primary benefit of Centralized Logging?
  • In a Data Loss Prevention (DLP) architecture, which component is commonly used to block USB devices at endpoints?
  • When selecting containment actions under limited resources, which factors should guide the sequence?
  • Explain encryption at rest vs encryption in transit, and why both are necessary for data protection.
  • Attackers sometimes change file timestamps to evade detection. Which concept addresses this risk through time synchronization?
  • Meterpreter is a payload used within the Metasploit Framework for what purpose?
  • Which of the following correctly identifies time synchronization protocols for precise sequencing?
  • Which threat actor type is typically associated with political motives?
  • In incident response, what is the purpose of Playbooks?
  • Which practice minimizes the data exposed in a breach by design?
  • What is the concept of separation of duties and how does it apply to privilege management?
  • What term describes an attack that injects malicious samples into a machine learning training dataset to corrupt the model's behavior?
  • What are SIEM correlation rules, and provide an example of a rule that detects anomalous authentication behavior?
  • What is data minimization and how does it help reduce incident impact?
  • Which OS feature is commonly abused by attackers for persistence, such as cron or Task Scheduler?
  • Lateral movement within a network often relies on attacker techniques to access additional assets. Which technique is commonly used to move laterally by leveraging credentials on remote hosts?
  • Which pair of frameworks includes MITRE ATT&CK and ATLAS?
  • In ABAC, which factors are used to determine access decisions?
  • Which authentication mechanism enables one login for multiple applications using standards like SAML or OIDC?
  • Defensive OSINT is used to map what?
  • Which discovery category identifies perimeter devices and connections rather than internal hosts?
  • Remote File Inclusion (RFI) vulnerabilities involve including files from remote locations to execute code. Which option correctly identifies this vulnerability?
  • Which testing approaches are used for validating an organization's incident response plans (as tabletop, mock, and full simulation exercises)?
  • Which term describes publicly available information used to inform threat intelligence and defense?
  • Given limited SOC resources, how would you prioritize incident containment actions when business operations must continue?
  • Which indicators would suggest Command-and-Control (C2) activity in network traffic?
  • What is the practice of integrating security into every SDLC phase called?
  • Explain the difference between network segmentation, micro-segmentation, and zero trust, and why they matter in security operations.
  • What cloud security controls are essential for IaaS, PaaS, and SaaS environments?
  • Which statement describes the purpose of 'Strings' in binary analysis?
  • Which technique in digital forensics extracts files from unallocated space without relying on metadata?
  • Which risk response involves shifting risk to another party, often via insurance?
  • In the Windows Registry, which root key contains settings applied to all users on the computer?
  • Predefined, repeatable incident response procedures for specific scenarios guiding human decisions.
  • What best describes Input Validation as a security practice?
  • What term describes unauthorized devices on a network that should be identified via 802.1X/NAC?
  • Which factors influence vulnerability remediation prioritization?
  • What is the primary objective of the recovery phase in incident response?
  • What is the primary purpose of a SOC playbook?
  • What is an escalation path in a SOC, and why is timely escalation critical?
  • Which impact level corresponds to an existential shutdown?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy