Security Operations & Incident Response Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Operations & Incident Response flashcards as text
During a security incident, the FIRST priority after detecting a compromise should be to:
Answer: Contain the affected systems to prevent further spread
Containment is the first operational priority to limit damage and prevent lateral movement before other steps.
Which SIEM correlation rule would BEST detect a brute-force attack against SSH?
Answer: More than 5 failed logins from the same IP within 60 seconds
Brute-force is characterized by rapid repeated failures from the same source, so a threshold-based rule within a short timeframe is most accurate.
A SOC analyst observes outbound traffic to an IP address flagged in threat intelligence feeds. What is the MOST appropriate initial response?
Answer: Block the IP at the firewall and investigate the affected host
Blocking the malicious IP stops ongoing communication while investigation of the host determines the scope and nature of compromise.
In incident response, 'lessons learned' meetings are PRIMARILY conducted to:
Answer: Improve future detection and response capabilities
Post-incident reviews focus on identifying what worked, what failed, and how to improve processes and defenses going forward.
Which log source would be MOST valuable when investigating potential data exfiltration via DNS?
Answer: DNS query logs from the recursive resolver
DNS query logs reveal unusually long subdomains or high query volumes to a single domain, both signatures of DNS tunneling exfiltration.
A 'runbook' in security operations is BEST described as:
Answer: A documented set of procedures for responding to specific incident types
Runbooks are step-by-step procedural guides that standardize analyst response to known incident scenarios.
What is the purpose of a 'canary token' in a security operations context?
Answer: To detect unauthorized access by triggering an alert when accessed
Canary tokens are fake credentials or files that alert defenders when accessed, indicating an attacker is moving through the environment.