Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Fighters in the War Against Cybercrime Quiz

Total questions: 35

Worksheet time: 18mins

Name
Class
Date
1.

What is the primary learning objective of "The SOC Analyst's Dilemma" scenario?

a)

To understand the basics of cybersecurity tools.

b)

To identify operational challenges in a SOC environment, focusing on alert fatigue, triage prioritization, and incident escalation.

c)

To learn how to configure SIEM dashboards.

d)

To study the history of cybersecurity incidents.

2.

What does the "High Severity" alert indicate in the scenario?

a)

Multiple failed logins followed by a successful login from an IP address in a country where the company has no employees.

b)

A virus detected in the company's network.

c)

Unauthorized access to the marketing director's email.

d)

A power outage in the company's data center.

3.

How many unread alerts are present in the SIEM dashboard at the start of the scenario?

a)

500

b)

450

c)

400

d)

350

4.

What does the company policy state regarding "High Severity" alerts?

a)

They must be triaged within 30 minutes.

b)

They must be triaged within 15 minutes.

c)

They must be ignored if there are distractions.

d)

They must be escalated immediately without triage.

5.

Based on a "High Severity" alert, which attack vector is most likely to be suspected?

a)

Phishing

b)

Denial of Service (DoS)

c)

Malware

d)

SQL Injection

6.

How does a backlog of 450 alerts impact your ability to judge the Critical Flag in a SOC Analyst's dilemma scenario?

a)

It makes the process faster

b)

It increases the likelihood of missing critical alerts

c)

It has no impact on decision-making

d)

It simplifies the identification of critical alerts

7.

What are the three key elements of a Security Operations Center (SOC) as shown in the diagram?

a)

Process, Technology, People

b)

Process, Security, Management

c)

Technology, Security, Operations

d)

People, Management, Threats

8.

What is the primary responsibility of a Tier 1 Alert Analyst in a SOC?

a)

Deep investigation of incidents and advising remediation.

b)

Monitoring incoming alerts and verifying true incidents.

c)

Managing all resources of the SOC and serving as the point of contact.

d)

Hunting for potential threats and implementing threat detection tools.

9.

What expertise is required for a Tier 3 Threat Hunter in a SOC?

a)

Monitoring incoming alerts and forwarding tickets.

b)

Managing resources and serving as the point of contact.

c)

Network, endpoint, threat intelligence, and malware reverse engineering.

d)

Advising remediation and action to be taken.

10.

Which SOC role is involved in hunting for potential threats and implementing threat detection tools?

a)

Tier 1 Alert Analyst

b)

Tier 2 Incident Responder

c)

Tier 3 Threat Hunter

d)

SOC Manager

11.

Which role in the SOC is responsible for threat intelligence according to the diagram?

a)

Tier 1 Alert Analyst

b)

SME/Threat Hunter (Threat Intel)

c)

Tier 2 Incident Responder

d)

SME/Threat Hunter (Endpoint)

12.

What happens if an alert is verified as a true security incident?

a)

It is dismissed as a false alarm

b)

It is forwarded to investigators or other security personnel

c)

It is sent to Tier 3 personnel directly

d)

It is ignored until further alerts are generated

13.

What action is taken if a ticket cannot be resolved by Tier 2 personnel?

a)

It is dismissed as a false alarm

b)

It is forwarded to Tier 3 personnel

c)

It is sent back to Tier 1 for re-evaluation

d)

It is closed without further investigation

14.

What is one of the primary benefits of using SOAR platforms in large security operations (SecOps)?

a)

Reduces the need for cybersecurity analysts entirely

b)

Optimizes SOC by integrating threat intelligence and automating workflows

c)

Focuses only on manual security processes

d)

Limits the use of security tools and resources

15.

Which of the following is a function of SOAR technology as described in the diagram?

a)

Creates a customized platform that integrates and coordinates security tools

b)

Focuses on manual intervention for security processes

c)

Reduces efficiency in cybersecurity operations

d)

Limits the use of playbooks in security teams

16.

What role does automation play in SOAR platforms?

a)

It increases the need for human intervention in security processes

b)

It executes security processes with minimal human intervention, increasing efficiency

c)

It eliminates the need for security tools and resources

d)

It focuses solely on manual threat intelligence

17.

What is one of the primary functions of SOAR security platforms?

a)

To encrypt data for secure storage

b)

To gather alarm data from each component of the system

c)

To create firewalls for network protection

d)

To monitor employee productivity

18.

Which feature of SOAR security platforms helps automate complex incident response workflows?

a)

Integration as a means of automating workflows

b)

Manual investigation of cases

c)

Creation of new security protocols

d)

Employee training programs

19.

What is the purpose of pre-defined playbooks in SOAR security platforms?

a)

To store user credentials securely

b)

To enable automatic response to specific threats

c)

To monitor system performance

d)

To create new software applications

20.

How can playbooks in SOAR security platforms be initiated?

a)

By manual input only

b)

Automatically based on predefined rules or triggered by security personnel

c)

By external third-party software

d)

Through random system checks

21.

What does the metric "Dwell Time" measure in SOC performance?

a)

The average time it takes for SOC personnel to identify valid security incidents.

b)

The time required to stop the spread of malware in the network.

c)

The length of time threat actors have access to a network before they are detected and their access is stopped.

d)

The time required to stop the incident from causing further damage to systems or data.

22.

Which SOC metric measures the average time it takes for SOC personnel to identify valid security incidents?

a)

Mean Time to Detect (MTTD).

b)

Mean Time to Respond (MTTR).

c)

Mean Time to Contain (MTTC).

d)

Time to Control.

23.

What does "Mean Time to Respond (MTTR)" refer to in SOC metrics?

a)

The average time it takes to stop and remediate a security incident.

b)

The time required to stop the spread of malware in the network.

c)

The average time it takes for SOC personnel to identify valid security incidents.

d)

The time required to stop the incident from causing further damage to systems or data.

24.

What is the benefit of implementing an enterprise-level SOC for medium and large networks?

a)

It provides a complete in-house solution.

b)

It outsources all operations to a security solutions provider.

c)

It eliminates the need for incident response teams.

d)

It focuses only on physical security measures.

25.

Which Cisco program focuses on safety and physical security?

a)

Cisco Managed Services.

b)

Cisco’s Safety and Physical Security Program.

c)

Cisco Tactical Operations (TacOps).

d)

Cisco Computer Security Incident Response Team (CSIRT).

26.

What is the basis for a business's tolerance for network downtime?

a)

The comparison of downtime cost to the cost of ensuring against downtime.

b)

The number of employees affected by downtime.

c)

The frequency of downtime occurrences.

d)

The type of industry the business operates in.

27.

What is the primary purpose of websites and mobile applications that advertise information technology jobs?

a)

To provide entertainment for job seekers.

b)

To target a variety of job applicants and provide tools for researching ideal job positions.

c)

To sell products related to technology.

d)

To create social media platforms for job seekers.

28.

Which of the following is an example of a job site aggregator?

a)

Amazon.com

b)

Indeed.com

c)

Wikipedia.org

d)

YouTube.com

29.

Which of the following websites is NOT mentioned as a source of career information in the text?

a)

CareerBuilder.com

b)

USAJobs.gov

c)

Glassdoor

d)

Monster.com

30.

What is the main advantage of integrating threat intelligence into SOAR platforms?

a)

It reduces the need for incident response teams.

b)

It enhances the accuracy of threat detection and response.

c)

It focuses solely on manual processes.

d)

It eliminates the use of security tools.

31.

Which role in a SOC is primarily responsible for analyzing and responding to security incidents?

a)

Tier 3 Threat Hunter

b)

Tier 2 Incident Responder

c)

Tier 1 Alert Analyst

d)

SOC Manager

32.

What does the term "alert fatigue" refer to in a SOC environment?

a)

The training provided to analysts to handle alerts.

b)

The time taken to respond to alerts.

c)

The overwhelming number of alerts leading to missed critical incidents.

d)

The process of prioritizing alerts based on severity.

33.

What is the primary function of a Tier 2 Incident Responder in a SOC?

a)

To hunt for potential threats and implement detection tools.

b)

To manage the SOC's resources and serve as the main point of contact.

c)

To conduct deep investigations and provide remediation advice.

d)

To monitor incoming alerts and verify incidents.

34.

Which of the following best describes the role of a SOC Manager?

a)

Conducting malware reverse engineering and threat analysis.

b)

Overseeing the entire SOC operations and managing personnel.

c)

Monitoring alerts and escalating incidents to Tier 3.

d)

Implementing security policies and procedures.

35.

What is the significance of the "Mean Time to Respond (MTTR)" metric in a SOC?

a)

It assesses the efficiency of the SOC in handling alerts.

b)

It measures the average time taken to detect security incidents.

c)

It indicates the time taken to contain a security incident after detection.

d)

It reflects the time taken to remediate a security incident.