NEW
Font size
WorksheetsDay 6 - Leadership
Total questions: 26
Worksheet time: 13mins
Which architecture best supports micro-segmentation in enterprise networks?
Flat network core
End-user device VLANs
Legacy protocol design
Network segmentation with policy
How does defense-in-depth reduce breach impact?
Removes human error
Reduces alert fatigue
Provides layered controls
Eliminates false positives
What is the primary benefit of TLS inspection for egress traffic?
Reducing storage needs
Better encryption strength
Faster routing decisions
Identifying hidden threats
Why are cloud security groups commonly used?
They prevent outages globally
They define security policy
They lower cost per VM
They increase performance
Which architecture aligns with Zero Trust principles?
Load balancing stickiness
Network zoning with policy
NAT-only perimeter
VPN tunneling only
Why should an organization standardize IAM roles across accounts?
For access control clarity
For UI consistency only
For DNS resolution speed
For password sharing ease
What risk increases when security tools are misconfigured?
Slower CPUs only
Missed attack chains
Patch delays only
Misconfigured detections
Which component validates server identity during HTTPS sessions?
IDS signatures
TLS certificates
SSL inspection box
Firewalls with NAT
How does Zero Trust handle internal application access?
Removes perimeter entirely
Enforces continuous verification
Blocks all traffic by default
Eliminates IAM dependencies
Why is understanding asset inventory critical for SOC operations?
Different vendors supported
Different OS versions
Different threat models
Different cabling types
What architecture decision most affects broadcast domain size?
IP addressing scheme
Time synchronization
VLAN sizing strategy
MTU settings only
Why is process automation valuable in a SOC?
Improves compliance forms
Speeds containment steps
Cuts costs without tradeoffs
Reduces staff entirely
What is the main advantage of a consolidated SIEM dashboard?
Faster, consistent triage
Better reports aesthetics
Easier audits only
Fewer alerts overall
Which metric better reflects response efficiency than tool count?
Number of tools used
Mean Time to Respond
Number of analysts hired
Ticket volume per hour
How does automation in SOAR typically impact triage?
Eliminates analyst review
Reduces repetitive tasks
Increases alert numbers
Prevents breaches always
Why should security run tabletop exercises regularly?
Tools expire frequently
Threats evolve continuously
Staff turnover solely
Compliance only goals
Which process best reduces false positives over time?
Tuning detections iteratively
Hiring staff immediately
More logging everywhere
Adding more tools quickly
What does a post-incident review primarily drive?
Visibility metrics only
Speed and consistency gains
Compliance checklists only
Network design changes
How does ticket prioritization improve SOC throughput?
Improves metric vanity
Reduces worklog length
Focuses on critical alerts
Simplifies reports only
What process failure most commonly leads to data exfiltration persistence?
DNS issues generally
Poor escalation paths
Weak encryption choices
Network latency spikes
What is a key benefit of implementing network segmentation in a Zero Trust model?
Limits lateral movement
Reduces need for encryption
Increases broadcast traffic
Removes authentication requirements
Which security control helps verify user identity before granting access to sensitive resources?
Multi-factor authentication
Network address translation
VLAN trunking
Load balancing
How does regular vulnerability scanning support SOC operations?
Detects misconfigurations and weaknesses
Improves network speed
Reduces staff workload entirely
Identifies outdated hardware
Which approach best limits unauthorized lateral movement within a network?
Using default credentials
Increasing bandwidth
Implementing network segmentation
Disabling all encryption
What is the main purpose of continuous monitoring in a SOC environment?
To automate password resets
To detect threats in real time
To increase ticket volume
To reduce hardware costs
Which security measure most effectively verifies user identity during remote access?
Static IP assignment
Multi-factor authentication
Disabling firewalls
Increasing VLAN count
