Skip to content

Security Operations Questions

Practice questions for Security Operations topic in CompTIA CySA+. 37 questions covering this domain.

37 questions13 easy13 medium11 hard
Q1
medium

An organization wants to improve its security operations by consolidating visibility across all security tools into a unified interface. Which process...

Q2
medium

A security analyst is investigating a phishing email that bypassed the spam filter. Which tool would be most appropriate for analyzing the email heade...

Q3
easy

Which framework uses tactics, techniques, and procedures (TTPs) to describe adversary behavior and is commonly referenced in threat intelligence?

Q4
hard

A SOC team is overwhelmed with low-fidelity alerts and wants to reduce analyst fatigue while maintaining detection coverage. Which process improvement...

Q5
medium

A SOC analyst notices a sudden and unexplained spike in outbound bandwidth from a workstation during off-hours. Which type of malicious activity does ...

Q6
easy

What is the role of threat hunting in a security operations program?

Q7
hard

A threat intelligence analyst at a financial services firm receives an ISAC report indicating that a specific threat actor group is targeting financia...

Q8
easy

Which type of threat actor is primarily motivated by financial gain?

Q9
easy

What does the term 'SIEM' stand for in security operations?

Q10
easy

Which of the following best describes a 'rogue device' as a network anomaly indicator?

Q11
hard

A threat hunter has been tasked with searching for living-off-the-land (LotL) techniques on Windows endpoints. Which tool and approach is most appropr...

Q12
medium

A security analyst is using VirusTotal to investigate a suspicious file hash. What type of tool is VirusTotal in the context of security operations?

Q13
medium

During a hunt, an analyst discovers an application on a workstation that is communicating with an external IP on an unusual port at regular intervals....

Q14
medium

An analyst wants to identify patterns in large volumes of security event data to distinguish normal from abnormal behavior. Which technique best suppo...

Q15
hard

An analyst observes that an internal host is performing DNS queries for randomized subdomain strings under a legitimate-looking domain at high frequen...

Q16
medium

A threat intelligence analyst is assessing a new indicator of compromise (IoC) shared by an ISAC. Which factor most directly determines how much weigh...

Q17
easy

Which scripting language is commonly used by security analysts for automating log analysis and threat detection tasks?

Q18
hard

A security analyst reviews SIEM alerts and finds that a privileged account logged in from two geographically distant locations within 30 minutes — a p...

Q19
hard

During an investigation, an analyst finds that a social engineering attack was used to convince an employee to install software granting remote access...

Q20
easy

What is the primary purpose of log ingestion in a security operations environment?

Sign in to see all 37 questions

Create a free account to browse all questions — completely free during our launch phase.