WorksheetsFighters in the War Against Cybercrime Quiz
Total questions: 35
Worksheet time: 18mins
What is the primary learning objective of "The SOC Analyst's Dilemma" scenario?
To understand the basics of cybersecurity tools.
To identify operational challenges in a SOC environment, focusing on alert fatigue, triage prioritization, and incident escalation.
To learn how to configure SIEM dashboards.
To study the history of cybersecurity incidents.
What does the "High Severity" alert indicate in the scenario?
Multiple failed logins followed by a successful login from an IP address in a country where the company has no employees.
A virus detected in the company's network.
Unauthorized access to the marketing director's email.
A power outage in the company's data center.
How many unread alerts are present in the SIEM dashboard at the start of the scenario?
500
450
400
350
What does the company policy state regarding "High Severity" alerts?
They must be triaged within 30 minutes.
They must be triaged within 15 minutes.
They must be ignored if there are distractions.
They must be escalated immediately without triage.
Based on a "High Severity" alert, which attack vector is most likely to be suspected?
Phishing
Denial of Service (DoS)
Malware
SQL Injection
How does a backlog of 450 alerts impact your ability to judge the Critical Flag in a SOC Analyst's dilemma scenario?
It makes the process faster
It increases the likelihood of missing critical alerts
It has no impact on decision-making
It simplifies the identification of critical alerts
What are the three key elements of a Security Operations Center (SOC) as shown in the diagram?
Process, Technology, People
Process, Security, Management
Technology, Security, Operations
People, Management, Threats
What is the primary responsibility of a Tier 1 Alert Analyst in a SOC?
Deep investigation of incidents and advising remediation.
Monitoring incoming alerts and verifying true incidents.
Managing all resources of the SOC and serving as the point of contact.
Hunting for potential threats and implementing threat detection tools.
What expertise is required for a Tier 3 Threat Hunter in a SOC?
Monitoring incoming alerts and forwarding tickets.
Managing resources and serving as the point of contact.
Network, endpoint, threat intelligence, and malware reverse engineering.
Advising remediation and action to be taken.
Which SOC role is involved in hunting for potential threats and implementing threat detection tools?
Tier 1 Alert Analyst
Tier 2 Incident Responder
Tier 3 Threat Hunter
SOC Manager
Which role in the SOC is responsible for threat intelligence according to the diagram?
Tier 1 Alert Analyst
SME/Threat Hunter (Threat Intel)
Tier 2 Incident Responder
SME/Threat Hunter (Endpoint)
What happens if an alert is verified as a true security incident?
It is dismissed as a false alarm
It is forwarded to investigators or other security personnel
It is sent to Tier 3 personnel directly
It is ignored until further alerts are generated
What action is taken if a ticket cannot be resolved by Tier 2 personnel?
It is dismissed as a false alarm
It is forwarded to Tier 3 personnel
It is sent back to Tier 1 for re-evaluation
It is closed without further investigation
What is one of the primary benefits of using SOAR platforms in large security operations (SecOps)?
Reduces the need for cybersecurity analysts entirely
Optimizes SOC by integrating threat intelligence and automating workflows
Focuses only on manual security processes
Limits the use of security tools and resources
Which of the following is a function of SOAR technology as described in the diagram?
Creates a customized platform that integrates and coordinates security tools
Focuses on manual intervention for security processes
Reduces efficiency in cybersecurity operations
Limits the use of playbooks in security teams
What role does automation play in SOAR platforms?
It increases the need for human intervention in security processes
It executes security processes with minimal human intervention, increasing efficiency
It eliminates the need for security tools and resources
It focuses solely on manual threat intelligence
What is one of the primary functions of SOAR security platforms?
To encrypt data for secure storage
To gather alarm data from each component of the system
To create firewalls for network protection
To monitor employee productivity
Which feature of SOAR security platforms helps automate complex incident response workflows?
Integration as a means of automating workflows
Manual investigation of cases
Creation of new security protocols
Employee training programs
What is the purpose of pre-defined playbooks in SOAR security platforms?
To store user credentials securely
To enable automatic response to specific threats
To monitor system performance
To create new software applications
How can playbooks in SOAR security platforms be initiated?
By manual input only
Automatically based on predefined rules or triggered by security personnel
By external third-party software
Through random system checks
What does the metric "Dwell Time" measure in SOC performance?
The average time it takes for SOC personnel to identify valid security incidents.
The time required to stop the spread of malware in the network.
The length of time threat actors have access to a network before they are detected and their access is stopped.
The time required to stop the incident from causing further damage to systems or data.
Which SOC metric measures the average time it takes for SOC personnel to identify valid security incidents?
Mean Time to Detect (MTTD).
Mean Time to Respond (MTTR).
Mean Time to Contain (MTTC).
Time to Control.
What does "Mean Time to Respond (MTTR)" refer to in SOC metrics?
The average time it takes to stop and remediate a security incident.
The time required to stop the spread of malware in the network.
The average time it takes for SOC personnel to identify valid security incidents.
The time required to stop the incident from causing further damage to systems or data.
What is the benefit of implementing an enterprise-level SOC for medium and large networks?
It provides a complete in-house solution.
It outsources all operations to a security solutions provider.
It eliminates the need for incident response teams.
It focuses only on physical security measures.
Which Cisco program focuses on safety and physical security?
Cisco Managed Services.
Cisco’s Safety and Physical Security Program.
Cisco Tactical Operations (TacOps).
Cisco Computer Security Incident Response Team (CSIRT).
What is the basis for a business's tolerance for network downtime?
The comparison of downtime cost to the cost of ensuring against downtime.
The number of employees affected by downtime.
The frequency of downtime occurrences.
The type of industry the business operates in.
What is the primary purpose of websites and mobile applications that advertise information technology jobs?
To provide entertainment for job seekers.
To target a variety of job applicants and provide tools for researching ideal job positions.
To sell products related to technology.
To create social media platforms for job seekers.
Which of the following is an example of a job site aggregator?
Amazon.com
Indeed.com
Wikipedia.org
YouTube.com
Which of the following websites is NOT mentioned as a source of career information in the text?
CareerBuilder.com
USAJobs.gov
Glassdoor
Monster.com
What is the main advantage of integrating threat intelligence into SOAR platforms?
It reduces the need for incident response teams.
It enhances the accuracy of threat detection and response.
It focuses solely on manual processes.
It eliminates the use of security tools.
Which role in a SOC is primarily responsible for analyzing and responding to security incidents?
Tier 3 Threat Hunter
Tier 2 Incident Responder
Tier 1 Alert Analyst
SOC Manager
What does the term "alert fatigue" refer to in a SOC environment?
The training provided to analysts to handle alerts.
The time taken to respond to alerts.
The overwhelming number of alerts leading to missed critical incidents.
The process of prioritizing alerts based on severity.
What is the primary function of a Tier 2 Incident Responder in a SOC?
To hunt for potential threats and implement detection tools.
To manage the SOC's resources and serve as the main point of contact.
To conduct deep investigations and provide remediation advice.
To monitor incoming alerts and verify incidents.
Which of the following best describes the role of a SOC Manager?
Conducting malware reverse engineering and threat analysis.
Overseeing the entire SOC operations and managing personnel.
Monitoring alerts and escalating incidents to Tier 3.
Implementing security policies and procedures.
What is the significance of the "Mean Time to Respond (MTTR)" metric in a SOC?
It assesses the efficiency of the SOC in handling alerts.
It measures the average time taken to detect security incidents.
It indicates the time taken to contain a security incident after detection.
It reflects the time taken to remediate a security incident.
