← All CCP Flashcard Decks

SOC Operations & Alert Triage Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 SOC Operations & Alert Triage flashcards as text
  1. What is the primary purpose of normalizing log data within a SIEM?

    Answer: To convert disparate log formats into a common schema for correlation

    Log normalization translates logs from different sources into a unified format, enabling effective correlation and alerting across the environment.

  2. A SOC analyst observes a spike in outbound traffic to multiple external IPs on port 443 late at night. What threat scenario should be prioritized?

    Answer: Beaconing behavior associated with malware C2 communication

    Regular outbound connections to many external IPs on port 443 during off-hours is characteristic of malware beaconing to command-and-control infrastructure.

  3. Which indicator would MOST strongly suggest a compromised privileged account rather than a compromised standard user account?

    Answer: Authentication to domain controllers and mass access to sensitive directories

    Privileged account compromise is typically evidenced by authentication to domain controllers and unauthorized access to sensitive administrative resources.

  4. In alert triage, what does 'enrichment' refer to?

    Answer: Supplementing alert data with additional context from threat intel, CMDB, and other sources

    Alert enrichment involves adding contextual information — such as asset owner, threat intel hits, and geolocation — to help analysts make faster, better decisions.

  5. What is the role of a 'threat hunting' function in a mature SOC?

    Answer: To proactively search for threats that evaded automated detection

    Threat hunting proactively searches for attacker activity that automated tools and signature-based detections have missed, requiring analyst-led investigation.

  6. Which of the following BEST describes the 'Cyber Kill Chain' model's value for SOC operations?

    Answer: It helps analysts identify which attack phase an adversary is in to guide response

    The Cyber Kill Chain model maps attacker progression through phases, helping SOC analysts understand where in an attack they have visibility and where to intervene.

  7. An alert fires because a user account logged in from two countries within 30 minutes. What type of detection logic is this?

    Answer: Impossible travel anomaly detection

    Impossible travel detection flags authentication events that are geographically improbable within the observed timeframe, indicating potential account compromise.