wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

SOC Analyst

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

Which of the following tools is primarily used in Microsoft Sentinel for threat detection and response?

a)

Microsoft Defender for Cloud

b)

Azure Security Center

c)

Kusto Query Language (KQL)

d)

Microsoft Defender for Identity

2.

Which of the following is NOT a key responsibility of a SOC Analyst?

a)

Threat hunting

b)

Network security monitoring

c)

Application development

d)

Incident response

3.

Which Microsoft security solution helps detect and respond to threats in Microsoft 365?

a)

Microsoft Defender for Office 365

b)

Microsoft Sentinel

c)

Microsoft Intune

d)

Azure Active Directory

4.

What is the default retention period for logs in Microsoft Sentinel?

a)

7 days

b)

30 days

c)

90 days

d)

365 days

5.

Which of the following is a common SOC monitoring tool used for real-time threat detection?

a)

Wireshark

b)

SolarWinds

c)

SIEM (Security Information and Event Management)

d)

Visual Studio Code

6.

Which of the following roles is responsible for investigating security incidents in Microsoft Defender?

a)

Security Administrator

b)

Compliance Officer

c)

Security Operations Analyst

d)

Network Engineer

7.

Which service in Microsoft Defender is specifically designed to protect endpoints?

a)

Microsoft Defender for Identity

b)

Microsoft Defender for Endpoint

c)

Microsoft Defender for Cloud

d)

Microsoft Defender for Office 365

8.

Which query language is used in Microsoft Sentinel to analyze security logs?

a)

SQL

b)

Python

c)

KQL (Kusto Query Language)

d)

PowerShell

9.

Which Microsoft service is used for analyzing and responding to identity-based threats?

a)

Microsoft Defender for Endpoint

b)

Microsoft Defender for Identity

c)

Microsoft Sentinel

d)

Microsoft Defender for Cloud

10.

What is the main purpose of a Security Orchestration, Automation, and Response (SOAR) tool?

a)

Automate security processes

b)

Develop security policies

c)

Replace SIEM systems

d)

Scan endpoints for vulnerabilities

11.

What type of attack involves flooding a network with excessive traffic to disrupt services?

a)

Phishing

b)

DDoS (Distributed Denial of Service)

c)

SQL Injection

d)

Man-in-the-Middle

12.

Which of the following is an example of a Security Incident?

a)

A failed login attempt

b)

A user forgetting their password

c)

Unauthorized access to a system

d)

A software update notification

13.

Which of the following helps reduce the impact of ransomware attacks?

a)

Keeping backups offline

b)

Using outdated antivirus software

c)

Allowing unrestricted access to users

d)

Disabling firewall protection

14.

Microsoft Sentinel is a cloud-based SIEM and SOAR solution.

a)

True

b)

False

15.

The MITRE ATT&CK framework is a knowledge base of adversary tactics and techniques.

a)

True

b)

False

16.

Zero Trust security model assumes that every request must be verified before granting access.

a)

True

b)

False

17.

A security alert is always a confirmed security incident.

a)

True

b)

False

18.

Which phase of the Incident Response process involves identifying and containing a security breach?

a)

Recovery

b)

Eradication

c)

Detection and Analysis

d)

Lessons Learned

19.

What is the primary goal of Threat Intelligence in SOC operations?

a)

Preventing all cyberattacks

b)

Identifying potential threats and vulnerabilities

c)

Blocking user access to all external websites

d)

Decreasing the SOC team’s workload

20.

Which of the following attack techniques involves an attacker gaining unauthorized access by stealing or guessing credentials?

a)

Lateral Movement

b)

Brute Force Attack

c)

Social Engineering

d)

Phishing

21.

Which of the following metrics is commonly used to measure the effectiveness of a SOC?

a)

MTTR (Mean Time to Respond)

b)

CPU Utilization

c)

Employee Turnover Rate

d)

Revenue Growth

22.

Threat Hunting in SOC operations is a proactive approach to identifying potential security threats.

a)

True

b)

False

23.

SOC analysts use network traffic analysis to detect abnormal behavior and potential security incidents.

a)

True

b)

False

24.

Which of the following security frameworks is widely used in SOCs for Incident Response?

a)

NIST Cybersecurity Framework

b)

Agile Development Framework

c)

ITIL (Information Technology Infrastructure Library)

d)

PRINCE2

25.

Which of the following is a critical SOC function for reducing false positives in security alerts?

a)

Patch Management

b)

Threat Intelligence Integration

c)

Increasing log retention period

d)

Disabling firewall rules