CCNA SECOPS 210-255 Exam
Complete Review with Verified Questions
And Answers (Latest Update)
Basic types of SOCs
ANSWER: 1) Threat-centric SOCs
2) Compliance-based SOCs
3) Operational-based SOCs
Basics of Threat-centric SOCs
ANSWER: + Proactively hunts for malicious threats
+ Focuses on addressing security across the entire attack continuum
Basics about the attack continuum and its objectives
ANSWER: + Before: shape policies and controls through contextual awareness
and in-depth analysis
+ During: continuously detect and block threats
+ After : Marginalize by identifying points of entry, determine scope, contain and
remediate, minimize risk of re-infection
Basics about Compliance-based SOCs
ANSWER: + comparing the compliance posture of systems to reference
configuration templates and standard system builds
,2|Page
+ detect unauthorized changes and existing configuration problems that could lead
to a security breach (before any attack).
What is the key to success in a Compliance-based SOCs? ANSWER: Linking an
organization's risk management and incident response practices to an automated
system compliance process. Automation is also important in other types of SOCs.
The difference between being compliant and being secure ANSWER: Being
compliant does not mean being secure because if there is no proper controls
implemented, things can be changed from compliant to non-compliant (by
hackers).
Basics about Operational-Based SOC
ANSWER: + Constantly monitoring the security posture of an organization's
internal network/systems.
+ Research, develop, and operationalize complex detection techniques that are
tailored for an organization's specific network environment.
What is CSIRT ?
ANSWER: Computer Security Incident Response Team (in operational based
SOC)
Log feeds include ANSWER: Full packet capture, netflow, protocol metadata,
application logs, machine logs, telemetry streams
Applications and analyst tools include ANSWER: log mining & analytics, network
packet mining, big data modeling and statistical analysis
,3|Page
SOC relies on a supporting infrastructure of these tools and systems
ANSWER: + Network mapping
+ Network monitoring
+ Vulnerability detection
+ Data collection
+ Threat and anomaly detection
+ Data aggregation and correlation
Samples of network security tools ANSWER: Wireshark, Netwitness, OSSEC,
NetFlow, Cisco Stealthwatch
What is the difference between vulnerability assessment and pen test?
ANSWER: Vulnerability assessment will be done first and be revised/re-run as
many times as needed. Organizations only perform pen test when they are
confident with the security posture after doing the vulnerability assessment(s).
This Security Onion component is used to query log data from the different sources
ANSWER: ELSA
Dynamic analysis ANSWER: the testing and evaluation of a program by executing
the data in real time to find errors
Log mining techniques ANSWER: + Sequencing + Path analysis + Log clustering
, 4|Page
Log clustering ANSWER: mine through large amounts of log data to build profiles
and to identify anomalous behavior.
Path analysis ANSWER: An interpretation of a chain of consecutive events that
occur during a set period of time. Path analysis is a way to understand an attacker's
behavior in order to gain actionable insights into log data.
Log mining techniques - Sequencing ANSWER: Reconstructing or following the
network traffic flow.
In order to detect data theft, an analyst must look at these types of data
ANSWER: data-in-motion, data-at-rest, and data-in-use and the compliance
information
Definition of Incident ANSWER: alerts or events that could pose a serious threat to
the organization and should be escalated to the incident response team
Some simple tasks SOC could automate ANSWER: Ticket generation, False
positive alert handling (by correlation, compare event with CVE db), report
generation
Volume-based anomaly alerts can come from these ANSWER: Statistical analysis,
Frequency analysis, Time-series forecasting
SOC - Tier 1 responsibilities ANSWER: + Continuously monitoring of the alert
queue.