Skip to content

Domain 4.0 — Security Operations

← Back to Security+ overview · Domain weight: 28% (largest domain)

Q079. SIEM

A security team aggregates logs from firewalls, servers, identity systems, and cloud services, then correlates events and generates alerts. What tool is this?

  • A. SIEM
  • B. UPS
  • C. TPM
  • D. CDN

Answer: A — Security information and event management

Why: SIEMs collect, normalize, correlate, alert, and support investigations across log sources.


Q080. SOAR

A system automatically enriches an alert with threat intelligence, opens a ticket, and disables a compromised account after analyst approval. What is this?

  • A. SOAR
  • B. SNMP
  • C. NAT
  • D. RAID

Answer: A — Security orchestration, automation, and response

Why: SOAR automates and orchestrates response workflows across tools.


Q081. IDS vs IPS

A device monitors mirrored traffic and alerts on suspicious activity but does not block packets. What is it?

  • A. IDS
  • B. IPS
  • C. NAT gateway
  • D. WAF only

Answer: A — IDS

Why: IDS detects and alerts. IPS is inline and can block.


Q082. IPS

A network device sits inline and drops packets matching exploit signatures. What is it?

  • A. IPS
  • B. IDS
  • C. Packet broker only
  • D. Syslog server

Answer: A — IPS

Why: An IPS can actively prevent traffic by blocking inline.


Q083. Firewall rule order

A firewall has a broad deny any any rule above a specific allow HTTPS to webserver rule. Users cannot reach the webserver. Why?

  • A. Rules are usually processed top-down and first match wins
  • B. HTTPS cannot pass through firewalls
  • C. Deny rules only apply to UDP
  • D. Web servers require FTP

Answer: A — Rules are usually processed top-down and first match wins

Why: Rule order matters. A broad deny above the allow prevents the allow from being evaluated.


Q084. Vulnerability scan vs penetration test

A tool identifies missing patches and weak configurations without exploiting them. What activity is this?

  • A. Vulnerability scanning
  • B. Penetration testing
  • C. Tabletop exercise
  • D. Legal hold

Answer: A — Vulnerability scanning

Why: Vulnerability scans identify likely weaknesses. Penetration tests attempt exploitation within rules of engagement.


Q085. Penetration test rules

Before a penetration test begins, what document should define scope, allowed techniques, timing, and contacts?

  • A. Rules of engagement
  • B. Acceptable use policy
  • C. Data retention schedule
  • D. Certificate signing request

Answer: A — Rules of engagement

Why: ROE prevents accidental business disruption and legal ambiguity.


Q086. False positive

A SIEM alert says malware executed on a host, but investigation shows the event was a sanctioned admin tool and no malicious behavior occurred. What was the alert?

  • A. False positive
  • B. False negative
  • C. True positive
  • D. True negative

Answer: A — False positive

Why: The alert indicated a problem that was not actually malicious.


Q087. False negative

An attack occurs but no alert fires. What is this?

  • A. False negative
  • B. False positive
  • C. True positive
  • D. True negative

Answer: A — False negative

Why: The security tool failed to detect a real event.


Q088. Log integrity

Which control best helps prove logs were not altered after collection?

  • A. Hashing/signing logs and sending them to centralized write-restricted storage
  • B. Keeping logs only on the compromised host
  • C. Disabling time sync
  • D. Rotating logs every minute without archival

Answer: A — Hashing/signing logs and sending them to centralized write-restricted storage

Why: Centralized, access-controlled, integrity-protected logs are stronger evidence.


Q089. Time synchronization

Why is NTP important for security investigations?

  • A. It aligns timestamps across systems for correlation
  • B. It encrypts all logs
  • C. It prevents phishing
  • D. It replaces endpoint protection

Answer: A — It aligns timestamps across systems for correlation

Why: Accurate timelines depend on synchronized clocks.


Q090. Chain of custody

A laptop is collected for forensic analysis. What is the purpose of chain-of-custody documentation?

  • A. Track who handled evidence, when, and why
  • B. Speed up DHCP assignment
  • C. Encrypt all evidence automatically
  • D. Replace legal approval

Answer: A — Track who handled evidence, when, and why

Why: Chain of custody supports evidence integrity and admissibility.


Q091. Evidence acquisition

What should be done before forensic analysis of a disk whenever feasible?

  • A. Create a forensic image and verify its hash
  • B. Boot the suspect OS and browse files
  • C. Delete temporary files
  • D. Patch the system first

Answer: A — Create a forensic image and verify its hash

Why: Analysts work from verified copies to preserve original evidence.


Q092. Volatile evidence

Which item should usually be collected earliest because it disappears when power is lost?

  • A. RAM contents
  • B. Printed policy
  • C. Archived backup tape
  • D. Asset tag sticker

Answer: A — RAM contents

Why: Volatile memory can contain running processes, network connections, decrypted keys, and malware artifacts.


Q093. Incident response: containment

A malware outbreak is spreading across workstations. The team disconnects affected hosts from the network. Which phase/activity is this?

  • A. Containment
  • B. Lessons learned
  • C. Preparation only
  • D. Risk acceptance

Answer: A — Containment

Why: Containment limits damage and prevents further spread.


Q094. Incident response: eradication

After containing malware, analysts remove persistence mechanisms and malicious files. What activity is this?

  • A. Eradication
  • B. Preparation
  • C. Reporting only
  • D. Tabletop exercise

Answer: A — Eradication

Why: Eradication removes the root cause and attacker artifacts.


Q095. Incident response: recovery

After reimaging infected systems, the team restores services and monitors for reinfection. What activity is this?

  • A. Recovery
  • B. Scoping only
  • C. Risk transfer
  • D. Reconnaissance

Answer: A — Recovery

Why: Recovery returns systems to normal operation and validates they are clean.


Q096. Lessons learned

After an incident, the team meets to document what worked, what failed, and what controls should change. What is this?

  • A. Lessons learned / post-incident activity
  • B. Initial access
  • C. Privilege escalation
  • D. Data exfiltration

Answer: A — Lessons learned / post-incident activity

Why: Post-incident review improves future detection, prevention, and response.


Q097. Playbook

A ransomware response document lists steps, decision points, communication templates, and responsible roles. What is this?

  • A. Incident response playbook
  • B. Data dictionary
  • C. Certificate policy only
  • D. Software bill of materials

Answer: A — Incident response playbook

Why: A playbook provides repeatable, scenario-specific response instructions.


Q098. Tabletop exercise

Executives and responders walk through a simulated data breach without touching production systems. What is this?

  • A. Tabletop exercise
  • B. Exploit chaining
  • C. Credential stuffing
  • D. Fuzzing

Answer: A — Tabletop exercise

Why: Tabletop exercises validate roles and decisions in a discussion-based scenario.


Q099. DLP

A tool blocks employees from emailing files containing customer credit card numbers to external recipients. What is this?

  • A. DLP
  • B. IDS
  • C. HSM
  • D. TPM

Answer: A — Data loss prevention

Why: DLP detects and blocks unauthorized movement of sensitive data.


Q100. Email security

Which DNS-based control helps receiving mail servers verify that an email server is authorized to send mail for a domain?

  • A. SPF
  • B. ARP
  • C. NTP
  • D. SMB

Answer: A — SPF

Why: SPF publishes authorized sending servers. DKIM signs mail; DMARC tells receivers how to handle SPF/DKIM failures.


Q101. DKIM

What does DKIM primarily provide for email?

  • A. Cryptographic signature of message headers/body by the sending domain
  • B. Password reset workflow
  • C. Network access control
  • D. Disk encryption

Answer: A — Cryptographic signature of message headers/body by the sending domain

Why: DKIM helps verify that mail was authorized by the domain and not altered in transit.


Q102. DMARC

A domain owner wants receiving systems to quarantine or reject mail that fails SPF/DKIM alignment. What DNS policy supports this?

  • A. DMARC
  • B. DHCP
  • C. SNMPv2
  • D. LDAP

Answer: A — DMARC

Why: DMARC builds on SPF and DKIM and defines recipient handling policy plus reporting.


Q103. Secure protocol replacement

Which protocol should replace Telnet for secure remote administration?

  • A. SSH
  • B. FTP
  • C. SNMPv1
  • D. HTTP

Answer: A — SSH

Why: SSH provides encrypted remote shell access. Telnet sends data in cleartext.


Q104. SNMP hardening

Which is the best choice for secure SNMP monitoring?

  • A. SNMPv3 with authentication and encryption
  • B. SNMPv1 public community string
  • C. SNMP over Telnet
  • D. Disable authentication for easier polling

Answer: A — SNMPv3 with authentication and encryption

Why: SNMPv3 supports stronger authentication and privacy features than earlier versions.


Q105. LDAP security

An application binds to a directory and transmits credentials. Which protocol should be used to protect the traffic?

  • A. LDAPS or LDAP with StartTLS
  • B. Plain LDAP only
  • C. TFTP
  • D. NetBIOS

Answer: A — LDAPS or LDAP with StartTLS

Why: Directory credentials should be protected with TLS.


Q106. Privileged access management

A company wants administrators to check out temporary privileged credentials, record sessions, and rotate passwords after use. What solution fits?

  • A. PAM
  • B. DLP
  • C. DNSSEC
  • D. NAC only

Answer: A — Privileged access management

Why: PAM controls, audits, and rotates high-risk privileged access.


Q107. JIT access

An engineer receives admin access only for a two-hour approved maintenance window. What concept is this?

  • A. Just-in-time access
  • B. Permanent privilege
  • C. Open authorization
  • D. Anonymous bind

Answer: A — Just-in-time access

Why: JIT grants privileges only when needed and for limited duration.


Q108. Password vault

Where should service account passwords and API keys be stored?

  • A. Secrets manager/password vault
  • B. Plaintext README file
  • C. Source code comments
  • D. Shared spreadsheet

Answer: A — Secrets manager/password vault

Why: Secrets tools provide access control, auditing, rotation, and encryption.


Q109. MFA fatigue

A user receives repeated push notifications and eventually approves one to make them stop. What attack is this?

  • A. MFA fatigue/push bombing
  • B. Birthday attack
  • C. Pharming
  • D. VLAN hopping

Answer: A — MFA fatigue/push bombing

Why: Attackers spam push approvals hoping the user accepts one.


Q110. Phishing-resistant MFA

Which authentication method is generally more resistant to phishing than SMS one-time codes?

  • A. FIDO2/WebAuthn security key
  • B. Security questions
  • C. Email OTP
  • D. Reused password with longer length

Answer: A — FIDO2/WebAuthn security key

Why: FIDO2/WebAuthn uses origin-bound cryptographic authentication that resists credential replay to fake sites.


Q111. Account lifecycle

A terminated employee's accounts remain active for 30 days. Which IAM process failed?

  • A. Deprovisioning
  • B. Federation
  • C. Tokenization
  • D. Load balancing

Answer: A — Deprovisioning

Why: Deprovisioning removes access when users leave or change roles.


Q112. Conditional access

A login from an unmanaged device in a foreign country requires stronger verification than a login from a managed laptop on a known network. What is this?

  • A. Conditional access
  • B. Static routing
  • C. Open relay
  • D. Hashing

Answer: A — Conditional access

Why: Access decisions change based on context such as device posture, location, risk, and identity.


Q113. Baselining

A monitoring system learns normal network traffic volumes and alerts when outbound traffic triples at 2 a.m. What technique is this?

  • A. Baselining/anomaly detection
  • B. Port knocking
  • C. Static NAT
  • D. Full-disk encryption

Answer: A — Baselining/anomaly detection

Why: Baselines define normal behavior so deviations can be investigated.


Q114. Threat hunting

Analysts proactively search for signs of attacker behavior without waiting for an alert. What is this?

  • A. Threat hunting
  • B. Risk transference
  • C. Change freeze
  • D. Secure disposal

Answer: A — Threat hunting

Why: Threat hunting is proactive, hypothesis-driven investigation.


Q115. File integrity monitoring

A web server's index.php changes unexpectedly and an alert fires. What control likely detected it?

  • A. File integrity monitoring
  • B. NAT
  • C. RAID
  • D. DHCP snooping

Answer: A — File integrity monitoring

Why: FIM detects unauthorized changes to critical files.


Q116. Endpoint isolation

An EDR console quarantines a laptop from the network but keeps management connectivity. What response action is this?

  • A. Isolation/containment
  • B. Risk avoidance
  • C. Data masking
  • D. Tokenization

Answer: A — Isolation/containment

Why: Isolation limits spread while allowing responders to investigate.


Q117. Backup restoration test

A company has nightly backups but never attempts to restore them. What is the main problem?

  • A. Backup recoverability is unproven
  • B. Backups automatically prevent phishing
  • C. Backups replace monitoring
  • D. Backups remove need for encryption

Answer: A — Backup recoverability is unproven

Why: A backup is only useful if it can be restored within business requirements.


Q118. Secure disposal

A company retires SSDs containing sensitive data. Which process reduces data remanence risk?

  • A. Sanitization/destruction following approved media handling procedures
  • B. Quick format only
  • C. Removing the drive label
  • D. Changing the hostname

Answer: A — Sanitization/destruction following approved media handling procedures

Why: Media must be wiped, cryptographically erased, degaussed where applicable, or physically destroyed based on type and sensitivity.


Q119. Automation risk

A SOAR playbook automatically blocks IPs from alerts. One bad rule blocks a major customer's VPN address. What control would reduce this risk?

  • A. Human approval or change control for high-impact actions
  • B. Remove all logging
  • C. Disable backups
  • D. Use weaker firewall rules

Answer: A — Human approval or change control for high-impact actions

Why: Automation needs guardrails, especially where false positives can cause outages.


Q120. Scripting use

A Linux admin writes a script to compare running services against an approved baseline and report drift. What security function does this support?

  • A. Configuration compliance monitoring
  • B. Cryptographic signing only
  • C. Voice phishing
  • D. Steganography

Answer: A — Configuration compliance monitoring

Why: Automation can detect unauthorized or accidental configuration changes.


Q198. UEBA impossible travel

A user successfully logs in from Dallas and five minutes later from Singapore with the same account. What detection concept applies?

  • A. Impossible travel anomaly
  • B. Normal password rotation
  • C. RAID failure
  • D. DNSSEC signing

Answer: A — Impossible travel anomaly

Why: UEBA and conditional access systems flag geographically impossible or improbable session patterns as high risk.


Q199. Sigma versus YARA

Which statement is most accurate?

  • A. Sigma describes log detection logic; YARA describes file/memory pattern matching rules
  • B. YARA is only for firewall routing
  • C. Sigma is a disk encryption algorithm
  • D. They are identical formats

Answer: A — Sigma describes log detection logic; YARA describes file/memory pattern matching rules

Why: Sigma is commonly used for SIEM/log detections. YARA is commonly used to identify malware patterns in files or memory. (See Q046 for the YARA basics this builds on.)


Q200. EDR containment tradeoff

A host is actively exfiltrating data. Forensics wants memory preserved, but the business wants the leak stopped. What is the best initial decision?

  • A. Isolate the host from the network while preserving power state when possible
  • B. Immediately wipe the disk
  • C. Turn off all logging
  • D. Email the attacker

Answer: A — Isolate the host from the network while preserving power state when possible

Why: Containment should stop active harm while preserving evidence where practical. Network isolation often preserves volatile state better than shutdown.


Q201. Cloud incident snapshot

A cloud VM is suspected of compromise. What action best preserves disk evidence before remediation?

  • A. Create a snapshot/image with metadata and restrict access
  • B. Run random cleanup scripts
  • C. Delete and recreate without recording anything
  • D. Disable audit logging

Answer: A — Create a snapshot/image with metadata and restrict access

Why: Snapshots preserve cloud disk state for investigation. Record metadata, identity, times, hashes where possible, and access controls.


← Domain 3 · Back to Security+ overview · Next: Domain 5 — Security Program Management →