📖 Tier 1: Prepare & Study Guide ✓ 100% Solved with Rationales

SOC Operations, Incident Response & Threat Defense (Computer Science) Solved Questions & Notes (2026) - Apex Rankers

General Competitive Exams > Computer Science > SOC Operations, Incident Response & Threat Defense

50 Total Solved Questions
~75 mins Estimated Reading Time
1 Subject Areas / Chapters
Select Topic Area / Chapter: Click any section below to switch questions

SOC Operations, Incident Response & Threat Defense

100%
Showing 25 of 50 (50%)
🎯 Practice
Jump:
Q. 1 Computer Aptitude Test
Difficulty: medium (1 Mark)
In enterprise network architecture: In a Security Operations Center (SOC), what is the core function of a SIEM (Security Information and Event Management) platform?
A
Aggregating, correlating, and analyzing real-time security log data from across the enterprise infrastructure to detect threats and trigger alerts
✓ Correct
B
Formatting monthly employee payroll slips
C
Printing hard-copy paper invoices for office supplies
D
Designing company website graphic animations
💡 Step-by-Step Explanation & Concept Rationale
SIEM systems ingest telemetry from firewalls, servers, endpoints, and identity systems, applying correlation rules and machine learning to identify security incidents.
Q. 2 Computer Aptitude Test
Difficulty: hard (1 Mark)
Under financial sector cybersecurity and IT governance frameworks, in a Security Operations Center (SOC), what is the core function of a SIEM (Security Information and Event Management) platform?
A
Printing hard-copy paper invoices for office supplies
B
Aggregating, correlating, and analyzing real-time security log data from across the enterprise infrastructure to detect threats and trigger alerts
✓ Correct
C
Designing company website graphic animations
D
Formatting monthly employee payroll slips
💡 Step-by-Step Explanation & Concept Rationale
SIEM systems ingest telemetry from firewalls, servers, endpoints, and identity systems, applying correlation rules and machine learning to identify security incidents.
Q. 3 Computer Aptitude Test
Difficulty: hard (1 Mark)
A Joint Director (IS&TD) overseeing network infrastructure evaluates: In a Security Operations Center (SOC), what is the core function of a SIEM (Security Information and Event Management) platform?
A
Designing company website graphic animations
B
Formatting monthly employee payroll slips
C
Aggregating, correlating, and analyzing real-time security log data from across the enterprise infrastructure to detect threats and trigger alerts
✓ Correct
D
Printing hard-copy paper invoices for office supplies
💡 Step-by-Step Explanation & Concept Rationale
SIEM systems ingest telemetry from firewalls, servers, endpoints, and identity systems, applying correlation rules and machine learning to identify security incidents.
Q. 4 Computer Aptitude Test
Difficulty: medium (1 Mark)
Regarding Cisco/Juniper enterprise routing and switching standards: In a Security Operations Center (SOC), what is the core function of a SIEM (Security Information and Event Management) platform?
A
Formatting monthly employee payroll slips
B
Printing hard-copy paper invoices for office supplies
C
Designing company website graphic animations
D
Aggregating, correlating, and analyzing real-time security log data from across the enterprise infrastructure to detect threats and trigger alerts
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
SIEM systems ingest telemetry from firewalls, servers, endpoints, and identity systems, applying correlation rules and machine learning to identify security incidents.
Q. 5 Computer Aptitude Test
Difficulty: hard (1 Mark)
In next-generation firewall and perimeter defense engineering, in a Security Operations Center (SOC), what is the core function of a SIEM (Security Information and Event Management) platform?
A
Aggregating, correlating, and analyzing real-time security log data from across the enterprise infrastructure to detect threats and trigger alerts
✓ Correct
B
Printing hard-copy paper invoices for office supplies
C
Designing company website graphic animations
D
Formatting monthly employee payroll slips
💡 Step-by-Step Explanation & Concept Rationale
SIEM systems ingest telemetry from firewalls, servers, endpoints, and identity systems, applying correlation rules and machine learning to identify security incidents.
Q. 6 Computer Aptitude Test
Difficulty: hard (1 Mark)
Under SOC operations and NIST incident response guidelines: In a Security Operations Center (SOC), what is the core function of a SIEM (Security Information and Event Management) platform?
A
Designing company website graphic animations
B
Aggregating, correlating, and analyzing real-time security log data from across the enterprise infrastructure to detect threats and trigger alerts
✓ Correct
C
Formatting monthly employee payroll slips
D
Printing hard-copy paper invoices for office supplies
💡 Step-by-Step Explanation & Concept Rationale
SIEM systems ingest telemetry from firewalls, servers, endpoints, and identity systems, applying correlation rules and machine learning to identify security incidents.
Q. 7 Computer Aptitude Test
Difficulty: medium (1 Mark)
Which architecture best delivers zero-trust security when considering: in a Security Operations Center (SOC), what is the core function of a SIEM (Security Information and Event Management) platform?
A
Formatting monthly employee payroll slips
B
Printing hard-copy paper invoices for office supplies
C
Aggregating, correlating, and analyzing real-time security log data from across the enterprise infrastructure to detect threats and trigger alerts
✓ Correct
D
Designing company website graphic animations
💡 Step-by-Step Explanation & Concept Rationale
SIEM systems ingest telemetry from firewalls, servers, endpoints, and identity systems, applying correlation rules and machine learning to identify security incidents.
Q. 8 Computer Aptitude Test
Difficulty: hard (1 Mark)
During enterprise disaster recovery and business continuity planning: In a Security Operations Center (SOC), what is the core function of a SIEM (Security Information and Event Management) platform?
A
Printing hard-copy paper invoices for office supplies
B
Designing company website graphic animations
C
Formatting monthly employee payroll slips
D
Aggregating, correlating, and analyzing real-time security log data from across the enterprise infrastructure to detect threats and trigger alerts
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
SIEM systems ingest telemetry from firewalls, servers, endpoints, and identity systems, applying correlation rules and machine learning to identify security incidents.
Q. 9 Computer Aptitude Test
Difficulty: medium (1 Mark)
In cryptographic infrastructure and public key management: In a Security Operations Center (SOC), what is the core function of a SIEM (Security Information and Event Management) platform?
A
Aggregating, correlating, and analyzing real-time security log data from across the enterprise infrastructure to detect threats and trigger alerts
✓ Correct
B
Designing company website graphic animations
C
Formatting monthly employee payroll slips
D
Printing hard-copy paper invoices for office supplies
💡 Step-by-Step Explanation & Concept Rationale
SIEM systems ingest telemetry from firewalls, servers, endpoints, and identity systems, applying correlation rules and machine learning to identify security incidents.
Q. 10 Computer Aptitude Test
Difficulty: hard (1 Mark)
From an IT operations and ISO/IEC 27001 compliance viewpoint: In a Security Operations Center (SOC), what is the core function of a SIEM (Security Information and Event Management) platform?
A
Formatting monthly employee payroll slips
B
Aggregating, correlating, and analyzing real-time security log data from across the enterprise infrastructure to detect threats and trigger alerts
✓ Correct
C
Printing hard-copy paper invoices for office supplies
D
Designing company website graphic animations
💡 Step-by-Step Explanation & Concept Rationale
SIEM systems ingest telemetry from firewalls, servers, endpoints, and identity systems, applying correlation rules and machine learning to identify security incidents.
Q. 11 Computer Aptitude Test
Difficulty: medium (1 Mark)
In enterprise network architecture: What are the standard 6 phases of the NIST Computer Security Incident Handling Guide (SP 800-61)?
A
Initiation, Execution, Stalling, Blaming, Settlement, and Termination
B
Scanning, Hacking, Erasing, Formatting, Reinstalling, and Forgetting
C
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned)
✓ Correct
D
Budgeting, Ordering, Assembling, Testing, Marketing, and Selling
💡 Step-by-Step Explanation & Concept Rationale
NIST SP 800-61 defines a structured incident response lifecycle from proactive readiness and rapid containment to root-cause eradication and lessons learned.
Q. 12 Computer Aptitude Test
Difficulty: hard (1 Mark)
Under financial sector cybersecurity and IT governance frameworks, what are the standard 6 phases of the NIST Computer Security Incident Handling Guide (SP 800-61)?
A
Scanning, Hacking, Erasing, Formatting, Reinstalling, and Forgetting
B
Budgeting, Ordering, Assembling, Testing, Marketing, and Selling
C
Initiation, Execution, Stalling, Blaming, Settlement, and Termination
D
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned)
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
NIST SP 800-61 defines a structured incident response lifecycle from proactive readiness and rapid containment to root-cause eradication and lessons learned.
Q. 13 Computer Aptitude Test
Difficulty: hard (1 Mark)
A Joint Director (IS&TD) overseeing network infrastructure evaluates: What are the standard 6 phases of the NIST Computer Security Incident Handling Guide (SP 800-61)?
A
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned)
✓ Correct
B
Budgeting, Ordering, Assembling, Testing, Marketing, and Selling
C
Initiation, Execution, Stalling, Blaming, Settlement, and Termination
D
Scanning, Hacking, Erasing, Formatting, Reinstalling, and Forgetting
💡 Step-by-Step Explanation & Concept Rationale
NIST SP 800-61 defines a structured incident response lifecycle from proactive readiness and rapid containment to root-cause eradication and lessons learned.
Q. 14 Computer Aptitude Test
Difficulty: medium (1 Mark)
Regarding Cisco/Juniper enterprise routing and switching standards: What are the standard 6 phases of the NIST Computer Security Incident Handling Guide (SP 800-61)?
A
Initiation, Execution, Stalling, Blaming, Settlement, and Termination
B
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned)
✓ Correct
C
Scanning, Hacking, Erasing, Formatting, Reinstalling, and Forgetting
D
Budgeting, Ordering, Assembling, Testing, Marketing, and Selling
💡 Step-by-Step Explanation & Concept Rationale
NIST SP 800-61 defines a structured incident response lifecycle from proactive readiness and rapid containment to root-cause eradication and lessons learned.
Q. 15 Computer Aptitude Test
Difficulty: hard (1 Mark)
In next-generation firewall and perimeter defense engineering, what are the standard 6 phases of the NIST Computer Security Incident Handling Guide (SP 800-61)?
A
Scanning, Hacking, Erasing, Formatting, Reinstalling, and Forgetting
B
Budgeting, Ordering, Assembling, Testing, Marketing, and Selling
C
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned)
✓ Correct
D
Initiation, Execution, Stalling, Blaming, Settlement, and Termination
💡 Step-by-Step Explanation & Concept Rationale
NIST SP 800-61 defines a structured incident response lifecycle from proactive readiness and rapid containment to root-cause eradication and lessons learned.
Q. 16 Computer Aptitude Test
Difficulty: hard (1 Mark)
Under SOC operations and NIST incident response guidelines: What are the standard 6 phases of the NIST Computer Security Incident Handling Guide (SP 800-61)?
A
Budgeting, Ordering, Assembling, Testing, Marketing, and Selling
B
Initiation, Execution, Stalling, Blaming, Settlement, and Termination
C
Scanning, Hacking, Erasing, Formatting, Reinstalling, and Forgetting
D
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned)
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
NIST SP 800-61 defines a structured incident response lifecycle from proactive readiness and rapid containment to root-cause eradication and lessons learned.
Q. 17 Computer Aptitude Test
Difficulty: medium (1 Mark)
Which architecture best delivers zero-trust security when considering: what are the standard 6 phases of the NIST Computer Security Incident Handling Guide (SP 800-61)?
A
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned)
✓ Correct
B
Initiation, Execution, Stalling, Blaming, Settlement, and Termination
C
Scanning, Hacking, Erasing, Formatting, Reinstalling, and Forgetting
D
Budgeting, Ordering, Assembling, Testing, Marketing, and Selling
💡 Step-by-Step Explanation & Concept Rationale
NIST SP 800-61 defines a structured incident response lifecycle from proactive readiness and rapid containment to root-cause eradication and lessons learned.
Q. 18 Computer Aptitude Test
Difficulty: hard (1 Mark)
During enterprise disaster recovery and business continuity planning: What are the standard 6 phases of the NIST Computer Security Incident Handling Guide (SP 800-61)?
A
Scanning, Hacking, Erasing, Formatting, Reinstalling, and Forgetting
B
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned)
✓ Correct
C
Budgeting, Ordering, Assembling, Testing, Marketing, and Selling
D
Initiation, Execution, Stalling, Blaming, Settlement, and Termination
💡 Step-by-Step Explanation & Concept Rationale
NIST SP 800-61 defines a structured incident response lifecycle from proactive readiness and rapid containment to root-cause eradication and lessons learned.
Q. 19 Computer Aptitude Test
Difficulty: medium (1 Mark)
In cryptographic infrastructure and public key management: What are the standard 6 phases of the NIST Computer Security Incident Handling Guide (SP 800-61)?
A
Budgeting, Ordering, Assembling, Testing, Marketing, and Selling
B
Initiation, Execution, Stalling, Blaming, Settlement, and Termination
C
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned)
✓ Correct
D
Scanning, Hacking, Erasing, Formatting, Reinstalling, and Forgetting
💡 Step-by-Step Explanation & Concept Rationale
NIST SP 800-61 defines a structured incident response lifecycle from proactive readiness and rapid containment to root-cause eradication and lessons learned.
Q. 20 Computer Aptitude Test
Difficulty: hard (1 Mark)
From an IT operations and ISO/IEC 27001 compliance viewpoint: What are the standard 6 phases of the NIST Computer Security Incident Handling Guide (SP 800-61)?
A
Initiation, Execution, Stalling, Blaming, Settlement, and Termination
B
Scanning, Hacking, Erasing, Formatting, Reinstalling, and Forgetting
C
Budgeting, Ordering, Assembling, Testing, Marketing, and Selling
D
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned)
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
NIST SP 800-61 defines a structured incident response lifecycle from proactive readiness and rapid containment to root-cause eradication and lessons learned.
Q. 21 Computer Aptitude Test
Difficulty: medium (1 Mark)
In enterprise network architecture: In threat intelligence analysis, what is an Indicator of Compromise (IoC)?
A
Forensic digital evidence (such as malicious IP addresses, suspicious file hashes, or registry keys) that indicates an IT system has been breached
✓ Correct
B
An official computer purchase invoice from a hardware vendor
C
The serial number of an office printer
D
The physical temperature of a server room air conditioner
💡 Step-by-Step Explanation & Concept Rationale
IoCs provide actionable telemetry that SOC analysts and EDR tools use to identify active compromises and hunt advanced persistent threats (APTs).
Q. 22 Computer Aptitude Test
Difficulty: hard (1 Mark)
Under financial sector cybersecurity and IT governance frameworks, in threat intelligence analysis, what is an Indicator of Compromise (IoC)?
A
The serial number of an office printer
B
Forensic digital evidence (such as malicious IP addresses, suspicious file hashes, or registry keys) that indicates an IT system has been breached
✓ Correct
C
The physical temperature of a server room air conditioner
D
An official computer purchase invoice from a hardware vendor
💡 Step-by-Step Explanation & Concept Rationale
IoCs provide actionable telemetry that SOC analysts and EDR tools use to identify active compromises and hunt advanced persistent threats (APTs).
Q. 23 Computer Aptitude Test
Difficulty: hard (1 Mark)
A Joint Director (IS&TD) overseeing network infrastructure evaluates: In threat intelligence analysis, what is an Indicator of Compromise (IoC)?
A
The physical temperature of a server room air conditioner
B
An official computer purchase invoice from a hardware vendor
C
Forensic digital evidence (such as malicious IP addresses, suspicious file hashes, or registry keys) that indicates an IT system has been breached
✓ Correct
D
The serial number of an office printer
💡 Step-by-Step Explanation & Concept Rationale
IoCs provide actionable telemetry that SOC analysts and EDR tools use to identify active compromises and hunt advanced persistent threats (APTs).
Q. 24 Computer Aptitude Test
Difficulty: medium (1 Mark)
Regarding Cisco/Juniper enterprise routing and switching standards: In threat intelligence analysis, what is an Indicator of Compromise (IoC)?
A
An official computer purchase invoice from a hardware vendor
B
The serial number of an office printer
C
The physical temperature of a server room air conditioner
D
Forensic digital evidence (such as malicious IP addresses, suspicious file hashes, or registry keys) that indicates an IT system has been breached
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
IoCs provide actionable telemetry that SOC analysts and EDR tools use to identify active compromises and hunt advanced persistent threats (APTs).
Q. 25 Computer Aptitude Test
Difficulty: hard (1 Mark)
In next-generation firewall and perimeter defense engineering, in threat intelligence analysis, what is an Indicator of Compromise (IoC)?
A
Forensic digital evidence (such as malicious IP addresses, suspicious file hashes, or registry keys) that indicates an IT system has been breached
✓ Correct
B
The serial number of an office printer
C
The physical temperature of a server room air conditioner
D
An official computer purchase invoice from a hardware vendor
💡 Step-by-Step Explanation & Concept Rationale
IoCs provide actionable telemetry that SOC analysts and EDR tools use to identify active compromises and hunt advanced persistent threats (APTs).
Study Stream Progress: Showing 25 of 50 Questions (50%)
Jump to:

Ready to Test Your Retention & Speed?

Now that you have reviewed the study questions and rationales, test yourself in our interactive 1-by-1 practice engine or take the full official timed mock exam.