CERTIFIED SOC ANALYST (CSA) EXAMINATION
QUESTIONS AND CORRECT
ANSWER&EXPLANATION|GRADED A+ STUDY GUIDE
SOUTHERN NEW HAMPSHIRE UNIVERSITY
1. The main role of a SOC analyst is to:
A. Manage accounting systems
B. Monitor and respond to security threats
C. Develop software applications
D. Install hardware
Answer: B
Rationale: SOC analysts detect and respond to security incidents.
2. SOC stands for:
A. System Operations Center
B. Security Operations Center
C. Secure Online Control
D. System Online Configuration
Answer: B
Rationale: SOC is Security Operations Center.
3. The primary goal of a SOC is to:
A. Improve sales
B. Protect organizational assets
C. Design networks
D. Build databases
Answer: B
Rationale: SOC focuses on cybersecurity defense.
4. SIEM stands for:
,A. Security Information and Event Management
B. System Integrated Email Manager
C. Secure Internet Event Monitoring
D. Security Incident Encryption Module
Answer: A
Rationale: SIEM collects and analyzes security data.
5. SIEM is used for:
A. Log collection and analysis
B. File storage
C. Software development
D. Hardware repair
Answer: A
Rationale: Centralized security monitoring.
6. A security incident is:
A. Any potential threat or breach
B. System update
C. Software installation
D. Network upgrade
Answer: A
Rationale: An event affecting security.
7. False positive in SOC means:
A. Alert with no real threat
B. Real attack
C. System crash
D. Network outage
Answer: A
Rationale: Incorrect alert.
8. False negative means:
, A. Real threat not detected
B. False alarm
C. System update
D. Log entry
Answer: A
Rationale: Missed detection.
9. SOC Tier 1 analysts handle:
A. Initial alert triage
B. Malware development
C. Network design
D. Database admin
Answer: A
Rationale: First-level response.
10. SOC Tier 2 analysts handle:
A. Incident investigation
B. HR tasks
C. Marketing
D. Hardware installation
Answer: A
Rationale: Deeper analysis.
11. SOC Tier 3 analysts handle:
A. Advanced threat hunting
B. Basic monitoring
C. Password resets
D. Office tasks
Answer: A
Rationale: Expert-level response.
12. Threat intelligence is:
QUESTIONS AND CORRECT
ANSWER&EXPLANATION|GRADED A+ STUDY GUIDE
SOUTHERN NEW HAMPSHIRE UNIVERSITY
1. The main role of a SOC analyst is to:
A. Manage accounting systems
B. Monitor and respond to security threats
C. Develop software applications
D. Install hardware
Answer: B
Rationale: SOC analysts detect and respond to security incidents.
2. SOC stands for:
A. System Operations Center
B. Security Operations Center
C. Secure Online Control
D. System Online Configuration
Answer: B
Rationale: SOC is Security Operations Center.
3. The primary goal of a SOC is to:
A. Improve sales
B. Protect organizational assets
C. Design networks
D. Build databases
Answer: B
Rationale: SOC focuses on cybersecurity defense.
4. SIEM stands for:
,A. Security Information and Event Management
B. System Integrated Email Manager
C. Secure Internet Event Monitoring
D. Security Incident Encryption Module
Answer: A
Rationale: SIEM collects and analyzes security data.
5. SIEM is used for:
A. Log collection and analysis
B. File storage
C. Software development
D. Hardware repair
Answer: A
Rationale: Centralized security monitoring.
6. A security incident is:
A. Any potential threat or breach
B. System update
C. Software installation
D. Network upgrade
Answer: A
Rationale: An event affecting security.
7. False positive in SOC means:
A. Alert with no real threat
B. Real attack
C. System crash
D. Network outage
Answer: A
Rationale: Incorrect alert.
8. False negative means:
, A. Real threat not detected
B. False alarm
C. System update
D. Log entry
Answer: A
Rationale: Missed detection.
9. SOC Tier 1 analysts handle:
A. Initial alert triage
B. Malware development
C. Network design
D. Database admin
Answer: A
Rationale: First-level response.
10. SOC Tier 2 analysts handle:
A. Incident investigation
B. HR tasks
C. Marketing
D. Hardware installation
Answer: A
Rationale: Deeper analysis.
11. SOC Tier 3 analysts handle:
A. Advanced threat hunting
B. Basic monitoring
C. Password resets
D. Office tasks
Answer: A
Rationale: Expert-level response.
12. Threat intelligence is: