SOC Monthly Flashcard

SOC Monthly Flashcard

Assessment

Flashcard

Computers

Professional Development

Hard

Created by

Quizizz Content

FREE Resource

Student preview

quiz-placeholder

10 questions

Show all answers

1.

FLASHCARD QUESTION

Front

A user reports receiving a suspicious email containing a link prompting them to enter their credentials. What is the FIRST step in investigating this phishing attempt?

Back

Analyze the email headers for sender details and authentication records

2.

FLASHCARD QUESTION

Front

A user reports that all their files have been encrypted with the .locked extension, and a ransom note is present. What is the IMMEDIATE action to take?

Back

Disconnect the infected machine from the network

3.

FLASHCARD QUESTION

Front

Your IDS detects multiple SQL injection attempts on a public-facing web server. What is the BEST response?

Back

Review web server logs and check for signs of successful exploitation

4.

FLASHCARD QUESTION

Front

What does the command
netsh advfirewall set allprofiles state off
do?

Back

It turns off the Windows Defender Firewall for all network profiles (Domain, Private, and Public).

5.

FLASHCARD QUESTION

Front

A brute-force attack has been detected against an exposed RDP server. What is the BEST mitigation strategy?

Back

Block the attacker's IP, enforce account lockout policies, and enable multi-factor authentication (MFA).

6.

FLASHCARD QUESTION

Front

Your DLP (Data Loss Prevention) alerts show large data uploads to a cloud storage service. What is the next step of action?

Back

Review SIEM and proxy logs to confirm the source, destination, and nature of the data transfer.

7.

FLASHCARD QUESTION

Front

Your SIEM system has flagged an alert indicating a high volume of failed login attempts followed by a successful login to an internal system using a corporate user's credentials. The account owner reports they did not attempt to log in, and the login was from an unrecognized IP address. What should be your FIRST course of action to mitigate the ATO attack?

Back

Immediately lock the account, force a password reset, and review the account's recent activity.

Create a free account and access millions of resources

Create resources
Host any resource
Get auto-graded reports
or continue with
Microsoft
Apple
Others
By signing up, you agree to our Terms of Service & Privacy Policy
Already have an account?