NEW
Font size
WorksheetsSOC Analyst
Total questions: 25
Worksheet time: 13mins
Which of the following tools is primarily used in Microsoft Sentinel for threat detection and response?
Microsoft Defender for Cloud
Azure Security Center
Kusto Query Language (KQL)
Microsoft Defender for Identity
Which of the following is NOT a key responsibility of a SOC Analyst?
Threat hunting
Network security monitoring
Application development
Incident response
Which Microsoft security solution helps detect and respond to threats in Microsoft 365?
Microsoft Defender for Office 365
Microsoft Sentinel
Microsoft Intune
Azure Active Directory
What is the default retention period for logs in Microsoft Sentinel?
7 days
30 days
90 days
365 days
Which of the following is a common SOC monitoring tool used for real-time threat detection?
Wireshark
SolarWinds
SIEM (Security Information and Event Management)
Visual Studio Code
Which of the following roles is responsible for investigating security incidents in Microsoft Defender?
Security Administrator
Compliance Officer
Security Operations Analyst
Network Engineer
Which service in Microsoft Defender is specifically designed to protect endpoints?
Microsoft Defender for Identity
Microsoft Defender for Endpoint
Microsoft Defender for Cloud
Microsoft Defender for Office 365
Which query language is used in Microsoft Sentinel to analyze security logs?
SQL
Python
KQL (Kusto Query Language)
PowerShell
Which Microsoft service is used for analyzing and responding to identity-based threats?
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Sentinel
Microsoft Defender for Cloud
What is the main purpose of a Security Orchestration, Automation, and Response (SOAR) tool?
Automate security processes
Develop security policies
Replace SIEM systems
Scan endpoints for vulnerabilities
What type of attack involves flooding a network with excessive traffic to disrupt services?
Phishing
DDoS (Distributed Denial of Service)
SQL Injection
Man-in-the-Middle
Which of the following is an example of a Security Incident?
A failed login attempt
A user forgetting their password
Unauthorized access to a system
A software update notification
Which of the following helps reduce the impact of ransomware attacks?
Keeping backups offline
Using outdated antivirus software
Allowing unrestricted access to users
Disabling firewall protection
Microsoft Sentinel is a cloud-based SIEM and SOAR solution.
True
False
The MITRE ATT&CK framework is a knowledge base of adversary tactics and techniques.
True
False
Zero Trust security model assumes that every request must be verified before granting access.
True
False
A security alert is always a confirmed security incident.
True
False
Which phase of the Incident Response process involves identifying and containing a security breach?
Recovery
Eradication
Detection and Analysis
Lessons Learned
What is the primary goal of Threat Intelligence in SOC operations?
Preventing all cyberattacks
Identifying potential threats and vulnerabilities
Blocking user access to all external websites
Decreasing the SOC team’s workload
Which of the following attack techniques involves an attacker gaining unauthorized access by stealing or guessing credentials?
Lateral Movement
Brute Force Attack
Social Engineering
Phishing
Which of the following metrics is commonly used to measure the effectiveness of a SOC?
MTTR (Mean Time to Respond)
CPU Utilization
Employee Turnover Rate
Revenue Growth
Threat Hunting in SOC operations is a proactive approach to identifying potential security threats.
True
False
SOC analysts use network traffic analysis to detect abnormal behavior and potential security incidents.
True
False
Which of the following security frameworks is widely used in SOCs for Incident Response?
NIST Cybersecurity Framework
Agile Development Framework
ITIL (Information Technology Infrastructure Library)
PRINCE2
Which of the following is a critical SOC function for reducing false positives in security alerts?
Patch Management
Threat Intelligence Integration
Increasing log retention period
Disabling firewall rules
