Security Operations & Incident Response Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Operations & Incident Response flashcards as text
Which technique is MOST effective for detecting fileless malware that executes entirely in memory?
Answer: Behavioral monitoring of process memory and anomalous script execution
Fileless malware leaves no disk artifacts, so behavioral detection of suspicious process behavior and in-memory script execution is necessary.
During an IR engagement, an analyst finds that the attacker established persistence via a scheduled task. Which Windows event log ID would confirm scheduled task creation?
Answer: Event ID 4698
Windows Security Event ID 4698 is logged when a scheduled task is created, making it the key artifact for this persistence mechanism.
A 'diamond model' of intrusion analysis focuses on the relationship between which four elements?
Answer: Adversary, capability, infrastructure, and victim
The Diamond Model structures intrusion analysis around the four core features: adversary, capability, infrastructure, and victim, and their interrelationships.
When should chain of custody documentation FIRST be initiated during a digital forensic investigation?
Answer: Before any evidence is collected or handled
Chain of custody must be established from the moment evidence is identified to ensure its integrity and admissibility throughout the investigation.
An attacker is using 'pass-the-hash' to move laterally in a Windows environment. Which control would MOST effectively mitigate this technique?
Answer: Implementing Credential Guard to protect NTLM hashes in a virtualized enclave
Windows Credential Guard uses virtualization-based security to isolate credential material, preventing attackers from extracting NTLM hashes from LSASS.
A SOC team is overwhelmed by alert fatigue. The BEST long-term solution is to:
Answer: Tune detection rules and implement SOAR playbooks to reduce noise and automate responses
Tuning reduces false positives at the source, while SOAR automation handles repetitive tasks, sustainably reducing analyst burden without missing real threats.
Which of the following BEST describes the role of a 'threat hunter' compared to a traditional SOC analyst?
Answer: Threat hunters proactively search for hidden adversaries using hypotheses rather than waiting for alerts
Threat hunting is a proactive, hypothesis-driven discipline that assumes compromise and searches for adversaries that have evaded automated detection.