01. A large enterprise has several semi-autonomous business units, each with its own systems and a different regulatory regime, and leadership wants both consistent standards and locally relevant response. The manager must choose an overall SOC structure.
Which structure best fits these conditions?
a) Outsource all units to one external provider to guarantee uniformity.
b) A federated model: central standards and shared intel, with local teams for context.
c) Fully independent SOCs per business unit with no central coordination.
d) A single fully centralized SOC handling every unit and regulatory regime identically, from one location.
02. Given a fixed budget that cannot monitor everything, a manager must decide where to concentrate a new SOC's detection coverage and analyst attention.
Which basis should drive that concentration?
a) Even coverage spread uniformly across every system the organization owns.
b) The newest technologies in the environment, since they are least understood.
c) The attack paths most likely to lead an adversary to the critical assets.
d) The systems that generate the highest raw volume of log data.
03. Planning the staffing for a new SOC, a manager's draft plan is to hire only generalist triage analysts and add other roles later.
Which consideration should most reshape that staffing plan?
a) The plan should copy the exact role breakdown of a peer organization's SOC.
b) The plan should defer all hiring until the SIEM and EDR are fully deployed.
c) The plan should simply hire as many triage analysts as the budget allows.
d) Plan a mix of specialist roles matched to the services the SOC will provide.
04. A company adopting a hybrid SOC must decide which functions to keep in-house and which to hand to its provider. It wants to retain the capabilities that depend on business context while offloading commodity work.
Which two choices reflect that principle?
(Choose two.)
a) Keep serious-incident investigation and response in-house.
b) Retain routine log-pipeline health monitoring as a core in-house capability.
c) Outsource threat-intelligence judgments about which of the company's specific adversaries and risks matter most.
d) Outsource high-volume first-line triage of common alerts to the provider.
05. Asked to justify how many analysts a new SOC needs, a manager wants a defensible, evidence-based estimate rather than a rule-of-thumb headcount.
Which two inputs should the sizing estimate be built on?
(Choose two.)
a) The number of analysts a similarly named competitor is reported to employ.
b) The seating capacity of the room set aside for the SOC.
c) The expected alert volume and the average handling time per alert.
d) The hours of coverage the organization has committed to provide.
06. A company handling sensitive proprietary data wants continuous coverage but insists that investigation of any serious incident stay with people who understand its business and systems. It cannot fund a full in-house night shift.
Which design best satisfies both requirements?
a) A hybrid model: the provider monitors after-hours, the in-house team owns investigation.
b) Keep everything in-house and extend the day team's hours with paid on-call.
c) Fully outsource the SOC, including incident investigation, to the provider.
d) Drop the continuous-coverage requirement and monitor only during business hours.
07. Intelligence suggests a stealthy actor may already be operating inside the environment, but no alerts have fired and the SOC's current detections cover only known signatures.
What should the manager initiate in response?
a) Wait for the SIEM to raise an alert if the actor takes any action.
b) Run a vulnerability scan of the exposed systems to find how the actor got in.
c) Increase log retention so the intrusion can be reconstructed later.
d) Launch a hypothesis-driven hunt for the actor's likely behaviors.
08. After a full quarter of structured hunting, the program has opened zero confirmed incidents. An executive proposes cutting it as ineffective, and the manager must judge the program's value on sound terms.
Which basis best reflects how a hunt program's value should be evaluated?
a) The percentage reduction in total SIEM alerts over the quarter.
b) The volume of raw log data the hunters queried across the quarter.
c) The new detections created and the coverage gaps confirmed closed.
d) The number of confirmed incidents and escalations the hunts produced during the period.
09. Frustrated by repeated intrusions, an executive asks the SOC manager to "go on the offensive" and disrupt the attacker's own systems. The manager must set the program's boundaries responsibly.
How should the manager scope active defense in response?
a) Keep active defense inside the organization's own systems; act against no outside host.
b) Scan the attacker's external hosts to enumerate their weaknesses for a future response.
c) Take no proactive measures at all and rely solely on preventive controls.
d) Authorize counter-attacks against the identified source infrastructure to deter future intrusions.
10. During a hunt, an analyst forms the hypothesis that an adversary is abusing scheduled tasks for persistence. Eager to act, the analyst proposes immediately pushing a blocking rule for scheduled-task creation across the estate.
What should the manager direct as the next step in the hunt?
a) Open a formal incident ticket and begin the response process.
b) Broaden the hunt to cover every known persistence technique at once.
c) Push the blocking rule now to shut down the technique before it can be used.
d) Determine what data would confirm or refute the hypothesis before acting.