Skip to content
Oluma Cyber Security Awareness
Security Operations Fundamentals — Practice Exam | Oluma Digital
Cert Zone · Security Operations

Security Operations Fundamentals

SOC-F

Oluma Digital Practice: Security Operations Fundamentals

This practice page helps learners review SOC fundamentals, security monitoring, alert triage, log analysis, SIEM/SOAR, threat intelligence, endpoint security, network monitoring, and operational response activities.

Managed by
Oluma Digital / Provider Neutral
Exam code
SOC-F
Level
Fundamentals
Delivery
Provider dependent
Duration
Practice assessment
Passing score
Study score only
Audience
Security and privacy learners
Questions here
100 practice items
Format
Multiple choice
Reference / official page → SOC-F

What this practice exam covers

Questions are grouped into study-friendly domains for certification and job-readiness review.

01

SOC foundations

SOC mission, analyst roles, alert triage, escalation, case management, and operational workflows.

02

Monitoring and detection

Logs, SIEM, EDR, XDR, IDS/IPS, network monitoring, detection logic, and alert quality.

03

Threat intelligence and hunting

Indicators, TTPs, MITRE ATT&CK, enrichment, hypothesis-driven hunting, and threat context.

04

Response and improvement

Containment support, ticket handling, metrics, lessons learned, SOAR, and continuous improvement.

These are unofficial practice questions. Always verify the current provider syllabus or official exam outline before testing.

Practice questions

Number of questions:

Pick a length, then choose an answer for instant feedback. Your score tracks below and counts only the questions you can see.

SOC foundations

Which option best describes Security Operations Center?

✓ Access granted.  Security Operations Center is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Security Operations Center. Security Operations Center is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Tier 1 analyst. What should it be associated with?

✓ Access granted.  The scenario points to Tier 1 analyst, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Tier 1 analyst. The scenario points to Tier 1 analyst, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Tier 2 analyst the BEST answer?

✓ Access granted.  Choose Tier 2 analyst when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Tier 2 analyst. Choose Tier 2 analyst when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Alert triage?

✓ Access granted.  Alert triage is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Alert triage. Alert triage is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Case management?

✓ Access granted.  Case management is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Case management. Case management is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Escalation process. What should it be associated with?

✓ Access granted.  The scenario points to Escalation process, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Escalation process. The scenario points to Escalation process, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Runbook the BEST answer?

✓ Access granted.  Choose Runbook when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Runbook. Choose Runbook when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Playbook?

✓ Access granted.  Playbook is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Playbook. Playbook is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes SIEM?

✓ Access granted.  SIEM is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: SIEM. SIEM is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing SOAR. What should it be associated with?

✓ Access granted.  The scenario points to SOAR, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving SOAR. The scenario points to SOAR, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is EDR the BEST answer?

✓ Access granted.  Choose EDR when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about EDR. Choose EDR when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to XDR?

✓ Access granted.  XDR is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: XDR. XDR is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes IDS?

✓ Access granted.  IDS is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: IDS. IDS is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing IPS. What should it be associated with?

✓ Access granted.  The scenario points to IPS, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving IPS. The scenario points to IPS, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Network security monitoring the BEST answer?

✓ Access granted.  Choose Network security monitoring when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Network security monitoring. Choose Network security monitoring when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Endpoint telemetry?

✓ Access granted.  Endpoint telemetry is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Endpoint telemetry. Endpoint telemetry is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Log source?

✓ Access granted.  Log source is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Log source. Log source is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Log normalization. What should it be associated with?

✓ Access granted.  The scenario points to Log normalization, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Log normalization. The scenario points to Log normalization, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Correlation rule the BEST answer?

✓ Access granted.  Choose Correlation rule when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Correlation rule. Choose Correlation rule when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Detection rule?

✓ Access granted.  Detection rule is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Detection rule. Detection rule is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes False positive?

✓ Access granted.  False positive is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: False positive. False positive is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing True positive. What should it be associated with?

✓ Access granted.  The scenario points to True positive, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving True positive. The scenario points to True positive, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Severity the BEST answer?

✓ Access granted.  Choose Severity when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Severity. Choose Severity when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Priority?

✓ Access granted.  Priority is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Priority. Priority is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Indicator of compromise?

✓ Access granted.  Indicator of compromise is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Indicator of compromise. Indicator of compromise is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Indicator of attack. What should it be associated with?

✓ Access granted.  The scenario points to Indicator of attack, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Indicator of attack. The scenario points to Indicator of attack, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Tactics techniques and procedures the BEST answer?

✓ Access granted.  Choose Tactics techniques and procedures when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Tactics techniques and procedures. Choose Tactics techniques and procedures when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to MITRE ATT&CK?

✓ Access granted.  MITRE ATT&CK is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: MITRE ATT&CK. MITRE ATT&CK is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Threat intelligence?

✓ Access granted.  Threat intelligence is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Threat intelligence. Threat intelligence is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Threat hunting. What should it be associated with?

✓ Access granted.  The scenario points to Threat hunting, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Threat hunting. The scenario points to Threat hunting, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Hypothesis-driven hunt the BEST answer?

✓ Access granted.  Choose Hypothesis-driven hunt when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Hypothesis-driven hunt. Choose Hypothesis-driven hunt when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Phishing analysis?

✓ Access granted.  Phishing analysis is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Phishing analysis. Phishing analysis is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Malware alert?

✓ Access granted.  Malware alert is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Malware alert. Malware alert is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Command and control. What should it be associated with?

✓ Access granted.  The scenario points to Command and control, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Command and control. The scenario points to Command and control, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Lateral movement the BEST answer?

✓ Access granted.  Choose Lateral movement when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Lateral movement. Choose Lateral movement when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Privilege escalation?

✓ Access granted.  Privilege escalation is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Privilege escalation. Privilege escalation is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Data exfiltration?

✓ Access granted.  Data exfiltration is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Data exfiltration. Data exfiltration is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing User behavior analytics. What should it be associated with?

✓ Access granted.  The scenario points to User behavior analytics, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving User behavior analytics. The scenario points to User behavior analytics, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Anomaly detection the BEST answer?

✓ Access granted.  Choose Anomaly detection when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Anomaly detection. Choose Anomaly detection when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Vulnerability alert?

✓ Access granted.  Vulnerability alert is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Vulnerability alert. Vulnerability alert is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Patch status?

✓ Access granted.  Patch status is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Patch status. Patch status is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Asset context. What should it be associated with?

✓ Access granted.  The scenario points to Asset context, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Asset context. The scenario points to Asset context, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Enrichment the BEST answer?

✓ Access granted.  Choose Enrichment when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Enrichment. Choose Enrichment when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Packet capture?

✓ Access granted.  Packet capture is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Packet capture. Packet capture is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes DNS log?

✓ Access granted.  DNS log is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: DNS log. DNS log is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Authentication log. What should it be associated with?

✓ Access granted.  The scenario points to Authentication log, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Authentication log. The scenario points to Authentication log, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Cloud audit log the BEST answer?

✓ Access granted.  Choose Cloud audit log when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Cloud audit log. Choose Cloud audit log when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Containment support?

✓ Access granted.  Containment support is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Containment support. Containment support is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Incident ticket?

✓ Access granted.  Incident ticket is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Incident ticket. Incident ticket is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing SOC metric. What should it be associated with?

✓ Access granted.  The scenario points to SOC metric, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving SOC metric. The scenario points to SOC metric, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Mean time to detect the BEST answer?

✓ Access granted.  Choose Mean time to detect when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Mean time to detect. Choose Mean time to detect when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Mean time to respond?

✓ Access granted.  Mean time to respond is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Mean time to respond. Mean time to respond is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes After-action review?

✓ Access granted.  After-action review is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: After-action review. After-action review is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Security Operations Center. What should it be associated with?

✓ Access granted.  The scenario points to Security Operations Center, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Security Operations Center. The scenario points to Security Operations Center, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Tier 1 analyst the BEST answer?

✓ Access granted.  Choose Tier 1 analyst when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Tier 1 analyst. Choose Tier 1 analyst when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Tier 2 analyst?

✓ Access granted.  Tier 2 analyst is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Tier 2 analyst. Tier 2 analyst is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Alert triage?

✓ Access granted.  Alert triage is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Alert triage. Alert triage is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Case management. What should it be associated with?

✓ Access granted.  The scenario points to Case management, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Case management. The scenario points to Case management, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Escalation process the BEST answer?

✓ Access granted.  Choose Escalation process when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Escalation process. Choose Escalation process when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Runbook?

✓ Access granted.  Runbook is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Runbook. Runbook is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Playbook?

✓ Access granted.  Playbook is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Playbook. Playbook is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing SIEM. What should it be associated with?

✓ Access granted.  The scenario points to SIEM, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving SIEM. The scenario points to SIEM, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is SOAR the BEST answer?

✓ Access granted.  Choose SOAR when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about SOAR. Choose SOAR when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to EDR?

✓ Access granted.  EDR is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: EDR. EDR is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes XDR?

✓ Access granted.  XDR is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: XDR. XDR is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing IDS. What should it be associated with?

✓ Access granted.  The scenario points to IDS, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving IDS. The scenario points to IDS, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is IPS the BEST answer?

✓ Access granted.  Choose IPS when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about IPS. Choose IPS when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Network security monitoring?

✓ Access granted.  Network security monitoring is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Network security monitoring. Network security monitoring is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Endpoint telemetry?

✓ Access granted.  Endpoint telemetry is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Endpoint telemetry. Endpoint telemetry is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Log source. What should it be associated with?

✓ Access granted.  The scenario points to Log source, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Log source. The scenario points to Log source, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Log normalization the BEST answer?

✓ Access granted.  Choose Log normalization when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Log normalization. Choose Log normalization when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Correlation rule?

✓ Access granted.  Correlation rule is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Correlation rule. Correlation rule is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Detection rule?

✓ Access granted.  Detection rule is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Detection rule. Detection rule is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing False positive. What should it be associated with?

✓ Access granted.  The scenario points to False positive, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving False positive. The scenario points to False positive, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is True positive the BEST answer?

✓ Access granted.  Choose True positive when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about True positive. Choose True positive when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Severity?

✓ Access granted.  Severity is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Severity. Severity is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Priority?

✓ Access granted.  Priority is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Priority. Priority is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Indicator of compromise. What should it be associated with?

✓ Access granted.  The scenario points to Indicator of compromise, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Indicator of compromise. The scenario points to Indicator of compromise, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Indicator of attack the BEST answer?

✓ Access granted.  Choose Indicator of attack when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Indicator of attack. Choose Indicator of attack when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Tactics techniques and procedures?

✓ Access granted.  Tactics techniques and procedures is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Tactics techniques and procedures. Tactics techniques and procedures is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes MITRE ATT&CK?

✓ Access granted.  MITRE ATT&CK is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: MITRE ATT&CK. MITRE ATT&CK is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Threat intelligence. What should it be associated with?

✓ Access granted.  The scenario points to Threat intelligence, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Threat intelligence. The scenario points to Threat intelligence, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Threat hunting the BEST answer?

✓ Access granted.  Choose Threat hunting when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Threat hunting. Choose Threat hunting when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Hypothesis-driven hunt?

✓ Access granted.  Hypothesis-driven hunt is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Hypothesis-driven hunt. Hypothesis-driven hunt is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Phishing analysis?

✓ Access granted.  Phishing analysis is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Phishing analysis. Phishing analysis is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Malware alert. What should it be associated with?

✓ Access granted.  The scenario points to Malware alert, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Malware alert. The scenario points to Malware alert, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Command and control the BEST answer?

✓ Access granted.  Choose Command and control when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Command and control. Choose Command and control when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Lateral movement?

✓ Access granted.  Lateral movement is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Lateral movement. Lateral movement is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Privilege escalation?

✓ Access granted.  Privilege escalation is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Privilege escalation. Privilege escalation is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Data exfiltration. What should it be associated with?

✓ Access granted.  The scenario points to Data exfiltration, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Data exfiltration. The scenario points to Data exfiltration, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is User behavior analytics the BEST answer?

✓ Access granted.  Choose User behavior analytics when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about User behavior analytics. Choose User behavior analytics when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Anomaly detection?

✓ Access granted.  Anomaly detection is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Anomaly detection. Anomaly detection is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Vulnerability alert?

✓ Access granted.  Vulnerability alert is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Vulnerability alert. Vulnerability alert is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing Patch status. What should it be associated with?

✓ Access granted.  The scenario points to Patch status, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving Patch status. The scenario points to Patch status, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Asset context the BEST answer?

✓ Access granted.  Choose Asset context when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Asset context. Choose Asset context when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Enrichment?

✓ Access granted.  Enrichment is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Enrichment. Enrichment is the relevant term; the other choices are unrelated distractors.
SOC foundations

Which option best describes Packet capture?

✓ Access granted.  Packet capture is the concept or activity most directly connected to this practice exam objective.
✗ Access denied.  Correct answer: Packet capture. Packet capture is the concept or activity most directly connected to this practice exam objective.
Monitoring and detection

A practitioner is reviewing DNS log. What should it be associated with?

✓ Access granted.  The scenario points to DNS log, which is part of the related professional knowledge area.
✗ Access denied.  Correct answer: A security, privacy, operations, engineering, or architecture activity involving DNS log. The scenario points to DNS log, which is part of the related professional knowledge area.
Threat intelligence and hunting

In an exam scenario, when is Authentication log the BEST answer?

✓ Access granted.  Choose Authentication log when the scenario asks for that control, process, design area, or management concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Authentication log. Choose Authentication log when the scenario asks for that control, process, design area, or management concept.
Response and improvement

Which item is MOST relevant to Cloud audit log?

✓ Access granted.  Cloud audit log is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Cloud audit log. Cloud audit log is the relevant term; the other choices are unrelated distractors.

Ready to keep building your skills?

Use this practice page to review terminology, processes, and exam-style decision points before moving into official or provider-specific study materials.

Unofficial practice questions created by Oluma Digital for study purposes. Not affiliated with or endorsed by IAPP, ISC2, OffSec, Cisco, Coursera, or any certification body. Always verify current objectives with the official provider.

0Correct0Answered25Visible