Domain 4.0 — Security Operations¶
← Back to Security+ overview · Domain weight: 28% (largest domain)
Q079. SIEM¶
A security team aggregates logs from firewalls, servers, identity systems, and cloud services, then correlates events and generates alerts. What tool is this?
- A. SIEM
- B. UPS
- C. TPM
- D. CDN
Answer: A — Security information and event management
Why: SIEMs collect, normalize, correlate, alert, and support investigations across log sources.
Q080. SOAR¶
A system automatically enriches an alert with threat intelligence, opens a ticket, and disables a compromised account after analyst approval. What is this?
- A. SOAR
- B. SNMP
- C. NAT
- D. RAID
Answer: A — Security orchestration, automation, and response
Why: SOAR automates and orchestrates response workflows across tools.
Q081. IDS vs IPS¶
A device monitors mirrored traffic and alerts on suspicious activity but does not block packets. What is it?
- A. IDS
- B. IPS
- C. NAT gateway
- D. WAF only
Answer: A — IDS
Why: IDS detects and alerts. IPS is inline and can block.
Q082. IPS¶
A network device sits inline and drops packets matching exploit signatures. What is it?
- A. IPS
- B. IDS
- C. Packet broker only
- D. Syslog server
Answer: A — IPS
Why: An IPS can actively prevent traffic by blocking inline.
Q083. Firewall rule order¶
A firewall has a broad deny any any rule above a specific allow HTTPS to webserver rule. Users cannot reach the webserver. Why?
- A. Rules are usually processed top-down and first match wins
- B. HTTPS cannot pass through firewalls
- C. Deny rules only apply to UDP
- D. Web servers require FTP
Answer: A — Rules are usually processed top-down and first match wins
Why: Rule order matters. A broad deny above the allow prevents the allow from being evaluated.
Q084. Vulnerability scan vs penetration test¶
A tool identifies missing patches and weak configurations without exploiting them. What activity is this?
- A. Vulnerability scanning
- B. Penetration testing
- C. Tabletop exercise
- D. Legal hold
Answer: A — Vulnerability scanning
Why: Vulnerability scans identify likely weaknesses. Penetration tests attempt exploitation within rules of engagement.
Q085. Penetration test rules¶
Before a penetration test begins, what document should define scope, allowed techniques, timing, and contacts?
- A. Rules of engagement
- B. Acceptable use policy
- C. Data retention schedule
- D. Certificate signing request
Answer: A — Rules of engagement
Why: ROE prevents accidental business disruption and legal ambiguity.
Q086. False positive¶
A SIEM alert says malware executed on a host, but investigation shows the event was a sanctioned admin tool and no malicious behavior occurred. What was the alert?
- A. False positive
- B. False negative
- C. True positive
- D. True negative
Answer: A — False positive
Why: The alert indicated a problem that was not actually malicious.
Q087. False negative¶
An attack occurs but no alert fires. What is this?
- A. False negative
- B. False positive
- C. True positive
- D. True negative
Answer: A — False negative
Why: The security tool failed to detect a real event.
Q088. Log integrity¶
Which control best helps prove logs were not altered after collection?
- A. Hashing/signing logs and sending them to centralized write-restricted storage
- B. Keeping logs only on the compromised host
- C. Disabling time sync
- D. Rotating logs every minute without archival
Answer: A — Hashing/signing logs and sending them to centralized write-restricted storage
Why: Centralized, access-controlled, integrity-protected logs are stronger evidence.
Q089. Time synchronization¶
Why is NTP important for security investigations?
- A. It aligns timestamps across systems for correlation
- B. It encrypts all logs
- C. It prevents phishing
- D. It replaces endpoint protection
Answer: A — It aligns timestamps across systems for correlation
Why: Accurate timelines depend on synchronized clocks.
Q090. Chain of custody¶
A laptop is collected for forensic analysis. What is the purpose of chain-of-custody documentation?
- A. Track who handled evidence, when, and why
- B. Speed up DHCP assignment
- C. Encrypt all evidence automatically
- D. Replace legal approval
Answer: A — Track who handled evidence, when, and why
Why: Chain of custody supports evidence integrity and admissibility.
Q091. Evidence acquisition¶
What should be done before forensic analysis of a disk whenever feasible?
- A. Create a forensic image and verify its hash
- B. Boot the suspect OS and browse files
- C. Delete temporary files
- D. Patch the system first
Answer: A — Create a forensic image and verify its hash
Why: Analysts work from verified copies to preserve original evidence.
Q092. Volatile evidence¶
Which item should usually be collected earliest because it disappears when power is lost?
- A. RAM contents
- B. Printed policy
- C. Archived backup tape
- D. Asset tag sticker
Answer: A — RAM contents
Why: Volatile memory can contain running processes, network connections, decrypted keys, and malware artifacts.
Q093. Incident response: containment¶
A malware outbreak is spreading across workstations. The team disconnects affected hosts from the network. Which phase/activity is this?
- A. Containment
- B. Lessons learned
- C. Preparation only
- D. Risk acceptance
Answer: A — Containment
Why: Containment limits damage and prevents further spread.
Q094. Incident response: eradication¶
After containing malware, analysts remove persistence mechanisms and malicious files. What activity is this?
- A. Eradication
- B. Preparation
- C. Reporting only
- D. Tabletop exercise
Answer: A — Eradication
Why: Eradication removes the root cause and attacker artifacts.
Q095. Incident response: recovery¶
After reimaging infected systems, the team restores services and monitors for reinfection. What activity is this?
- A. Recovery
- B. Scoping only
- C. Risk transfer
- D. Reconnaissance
Answer: A — Recovery
Why: Recovery returns systems to normal operation and validates they are clean.
Q096. Lessons learned¶
After an incident, the team meets to document what worked, what failed, and what controls should change. What is this?
- A. Lessons learned / post-incident activity
- B. Initial access
- C. Privilege escalation
- D. Data exfiltration
Answer: A — Lessons learned / post-incident activity
Why: Post-incident review improves future detection, prevention, and response.
Q097. Playbook¶
A ransomware response document lists steps, decision points, communication templates, and responsible roles. What is this?
- A. Incident response playbook
- B. Data dictionary
- C. Certificate policy only
- D. Software bill of materials
Answer: A — Incident response playbook
Why: A playbook provides repeatable, scenario-specific response instructions.
Q098. Tabletop exercise¶
Executives and responders walk through a simulated data breach without touching production systems. What is this?
- A. Tabletop exercise
- B. Exploit chaining
- C. Credential stuffing
- D. Fuzzing
Answer: A — Tabletop exercise
Why: Tabletop exercises validate roles and decisions in a discussion-based scenario.
Q099. DLP¶
A tool blocks employees from emailing files containing customer credit card numbers to external recipients. What is this?
- A. DLP
- B. IDS
- C. HSM
- D. TPM
Answer: A — Data loss prevention
Why: DLP detects and blocks unauthorized movement of sensitive data.
Q100. Email security¶
Which DNS-based control helps receiving mail servers verify that an email server is authorized to send mail for a domain?
- A. SPF
- B. ARP
- C. NTP
- D. SMB
Answer: A — SPF
Why: SPF publishes authorized sending servers. DKIM signs mail; DMARC tells receivers how to handle SPF/DKIM failures.
Q101. DKIM¶
What does DKIM primarily provide for email?
- A. Cryptographic signature of message headers/body by the sending domain
- B. Password reset workflow
- C. Network access control
- D. Disk encryption
Answer: A — Cryptographic signature of message headers/body by the sending domain
Why: DKIM helps verify that mail was authorized by the domain and not altered in transit.
Q102. DMARC¶
A domain owner wants receiving systems to quarantine or reject mail that fails SPF/DKIM alignment. What DNS policy supports this?
- A. DMARC
- B. DHCP
- C. SNMPv2
- D. LDAP
Answer: A — DMARC
Why: DMARC builds on SPF and DKIM and defines recipient handling policy plus reporting.
Q103. Secure protocol replacement¶
Which protocol should replace Telnet for secure remote administration?
- A. SSH
- B. FTP
- C. SNMPv1
- D. HTTP
Answer: A — SSH
Why: SSH provides encrypted remote shell access. Telnet sends data in cleartext.
Q104. SNMP hardening¶
Which is the best choice for secure SNMP monitoring?
- A. SNMPv3 with authentication and encryption
- B. SNMPv1 public community string
- C. SNMP over Telnet
- D. Disable authentication for easier polling
Answer: A — SNMPv3 with authentication and encryption
Why: SNMPv3 supports stronger authentication and privacy features than earlier versions.
Q105. LDAP security¶
An application binds to a directory and transmits credentials. Which protocol should be used to protect the traffic?
- A. LDAPS or LDAP with StartTLS
- B. Plain LDAP only
- C. TFTP
- D. NetBIOS
Answer: A — LDAPS or LDAP with StartTLS
Why: Directory credentials should be protected with TLS.
Q106. Privileged access management¶
A company wants administrators to check out temporary privileged credentials, record sessions, and rotate passwords after use. What solution fits?
- A. PAM
- B. DLP
- C. DNSSEC
- D. NAC only
Answer: A — Privileged access management
Why: PAM controls, audits, and rotates high-risk privileged access.
Q107. JIT access¶
An engineer receives admin access only for a two-hour approved maintenance window. What concept is this?
- A. Just-in-time access
- B. Permanent privilege
- C. Open authorization
- D. Anonymous bind
Answer: A — Just-in-time access
Why: JIT grants privileges only when needed and for limited duration.
Q108. Password vault¶
Where should service account passwords and API keys be stored?
- A. Secrets manager/password vault
- B. Plaintext README file
- C. Source code comments
- D. Shared spreadsheet
Answer: A — Secrets manager/password vault
Why: Secrets tools provide access control, auditing, rotation, and encryption.
Q109. MFA fatigue¶
A user receives repeated push notifications and eventually approves one to make them stop. What attack is this?
- A. MFA fatigue/push bombing
- B. Birthday attack
- C. Pharming
- D. VLAN hopping
Answer: A — MFA fatigue/push bombing
Why: Attackers spam push approvals hoping the user accepts one.
Q110. Phishing-resistant MFA¶
Which authentication method is generally more resistant to phishing than SMS one-time codes?
- A. FIDO2/WebAuthn security key
- B. Security questions
- C. Email OTP
- D. Reused password with longer length
Answer: A — FIDO2/WebAuthn security key
Why: FIDO2/WebAuthn uses origin-bound cryptographic authentication that resists credential replay to fake sites.
Q111. Account lifecycle¶
A terminated employee's accounts remain active for 30 days. Which IAM process failed?
- A. Deprovisioning
- B. Federation
- C. Tokenization
- D. Load balancing
Answer: A — Deprovisioning
Why: Deprovisioning removes access when users leave or change roles.
Q112. Conditional access¶
A login from an unmanaged device in a foreign country requires stronger verification than a login from a managed laptop on a known network. What is this?
- A. Conditional access
- B. Static routing
- C. Open relay
- D. Hashing
Answer: A — Conditional access
Why: Access decisions change based on context such as device posture, location, risk, and identity.
Q113. Baselining¶
A monitoring system learns normal network traffic volumes and alerts when outbound traffic triples at 2 a.m. What technique is this?
- A. Baselining/anomaly detection
- B. Port knocking
- C. Static NAT
- D. Full-disk encryption
Answer: A — Baselining/anomaly detection
Why: Baselines define normal behavior so deviations can be investigated.
Q114. Threat hunting¶
Analysts proactively search for signs of attacker behavior without waiting for an alert. What is this?
- A. Threat hunting
- B. Risk transference
- C. Change freeze
- D. Secure disposal
Answer: A — Threat hunting
Why: Threat hunting is proactive, hypothesis-driven investigation.
Q115. File integrity monitoring¶
A web server's index.php changes unexpectedly and an alert fires. What control likely detected it?
- A. File integrity monitoring
- B. NAT
- C. RAID
- D. DHCP snooping
Answer: A — File integrity monitoring
Why: FIM detects unauthorized changes to critical files.
Q116. Endpoint isolation¶
An EDR console quarantines a laptop from the network but keeps management connectivity. What response action is this?
- A. Isolation/containment
- B. Risk avoidance
- C. Data masking
- D. Tokenization
Answer: A — Isolation/containment
Why: Isolation limits spread while allowing responders to investigate.
Q117. Backup restoration test¶
A company has nightly backups but never attempts to restore them. What is the main problem?
- A. Backup recoverability is unproven
- B. Backups automatically prevent phishing
- C. Backups replace monitoring
- D. Backups remove need for encryption
Answer: A — Backup recoverability is unproven
Why: A backup is only useful if it can be restored within business requirements.
Q118. Secure disposal¶
A company retires SSDs containing sensitive data. Which process reduces data remanence risk?
- A. Sanitization/destruction following approved media handling procedures
- B. Quick format only
- C. Removing the drive label
- D. Changing the hostname
Answer: A — Sanitization/destruction following approved media handling procedures
Why: Media must be wiped, cryptographically erased, degaussed where applicable, or physically destroyed based on type and sensitivity.
Q119. Automation risk¶
A SOAR playbook automatically blocks IPs from alerts. One bad rule blocks a major customer's VPN address. What control would reduce this risk?
- A. Human approval or change control for high-impact actions
- B. Remove all logging
- C. Disable backups
- D. Use weaker firewall rules
Answer: A — Human approval or change control for high-impact actions
Why: Automation needs guardrails, especially where false positives can cause outages.
Q120. Scripting use¶
A Linux admin writes a script to compare running services against an approved baseline and report drift. What security function does this support?
- A. Configuration compliance monitoring
- B. Cryptographic signing only
- C. Voice phishing
- D. Steganography
Answer: A — Configuration compliance monitoring
Why: Automation can detect unauthorized or accidental configuration changes.
Q198. UEBA impossible travel¶
A user successfully logs in from Dallas and five minutes later from Singapore with the same account. What detection concept applies?
- A. Impossible travel anomaly
- B. Normal password rotation
- C. RAID failure
- D. DNSSEC signing
Answer: A — Impossible travel anomaly
Why: UEBA and conditional access systems flag geographically impossible or improbable session patterns as high risk.
Q199. Sigma versus YARA¶
Which statement is most accurate?
- A. Sigma describes log detection logic; YARA describes file/memory pattern matching rules
- B. YARA is only for firewall routing
- C. Sigma is a disk encryption algorithm
- D. They are identical formats
Answer: A — Sigma describes log detection logic; YARA describes file/memory pattern matching rules
Why: Sigma is commonly used for SIEM/log detections. YARA is commonly used to identify malware patterns in files or memory. (See Q046 for the YARA basics this builds on.)
Q200. EDR containment tradeoff¶
A host is actively exfiltrating data. Forensics wants memory preserved, but the business wants the leak stopped. What is the best initial decision?
- A. Isolate the host from the network while preserving power state when possible
- B. Immediately wipe the disk
- C. Turn off all logging
- D. Email the attacker
Answer: A — Isolate the host from the network while preserving power state when possible
Why: Containment should stop active harm while preserving evidence where practical. Network isolation often preserves volatile state better than shutdown.
Q201. Cloud incident snapshot¶
A cloud VM is suspected of compromise. What action best preserves disk evidence before remediation?
- A. Create a snapshot/image with metadata and restrict access
- B. Run random cleanup scripts
- C. Delete and recreate without recording anything
- D. Disable audit logging
Answer: A — Create a snapshot/image with metadata and restrict access
Why: Snapshots preserve cloud disk state for investigation. Record metadata, identity, times, hashes where possible, and access controls.
← Domain 3 · Back to Security+ overview · Next: Domain 5 — Security Program Management →