
Security Operations and Defense Analyst

Quiz
•
Computers
•
Professional Development
•
Easy

Neo 0101
Used 3+ times
FREE Resource
19 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which metric could help identify the following issue: A new data source was improperly configured and is generating a high volume of alerts
Total event volume
Events by Source type
Quality of Escalations
Index forwarding
2.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which metric could help identify the following issue? An existing connection was lost and we are no longer receiving messages from a source
Index forwarding
Quality of Escalations
Events by Source type
Total event volume
3.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which metric could help identify the following issue? Analysts are overwhelmed and are not able to fully investigate all incidents thoroughly
Quality of escalations
Events by Source type
Total event volume
Index forwarding
4.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What SOC metric measures, How long it took to detect a threat in the environment?
Dwell-time
MTTA
MTTR
MTTD
5.
MULTIPLE SELECT QUESTION
45 sec • 1 pt
What are other non-primary but important tasks that Cybersecurity Defense Analysts can perform to help improve Security Operations? (Select 3)
Get data, assets and identities into Splunk
Provide detailed documentation in their reports and notes for other teams and analysts
Request improvements and the development of dashboards, searches and tooling
Select protection tools that will be used in the organization
Share suggestions for automation and improved remediation steps
6.
MULTIPLE SELECT QUESTION
45 sec • 1 pt
According to the Blue Team Academy definitions, which of these activities are performed more often by the Cybersecurity Defense Analyst in a SOC? (Select 2)
Creating new detection rules
Threat Hunting
Alert triage
Ensuring data is brought to the corresponding SIEM
7.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
An Analyst is triaging a new event with the following alert message: "Authentication errors exceeded for user ST002".
During investigation, the Analyst finds evidence of attempts to use a dictionary attack to gain access to this account.
With the provided context, what disposition would you assign to this event?
True Positive
False Positive
Create a free account and access millions of resources
Similar Resources on Wayground
17 questions
Cyber Quiz

Quiz
•
Professional Development
15 questions
Sec Practice Quiz

Quiz
•
Professional Development
17 questions
FINAL REVISION _ 2 _ 2020

Quiz
•
Professional Development
15 questions
Sec+ Quiz - 2

Quiz
•
Professional Development
15 questions
IT Professionals A+ Review

Quiz
•
Professional Development
17 questions
Cyber Quiz

Quiz
•
Professional Development
15 questions
ELT with Fivetran Quiz

Quiz
•
Professional Development
15 questions
Data Analytics vs. Data Science vs. Data Engineering

Quiz
•
Professional Development
Popular Resources on Wayground
18 questions
Writing Launch Day 1

Lesson
•
3rd Grade
11 questions
Hallway & Bathroom Expectations

Quiz
•
6th - 8th Grade
11 questions
Standard Response Protocol

Quiz
•
6th - 8th Grade
40 questions
Algebra Review Topics

Quiz
•
9th - 12th Grade
4 questions
Exit Ticket 7/29

Quiz
•
8th Grade
10 questions
Lab Safety Procedures and Guidelines

Interactive video
•
6th - 10th Grade
19 questions
Handbook Overview

Lesson
•
9th - 12th Grade
20 questions
Subject-Verb Agreement

Quiz
•
9th Grade