✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Security Concepts
A SOC analyst reviews an alert generated by the intrusion detection system indicating a port scan against a critical server. After investigating packet captures and firewall logs, the analyst confirms that a port scan did in fact occur and that the alert accurately reflects this malicious activity. How should this alert be classified?
A true positive occurs when an alert correctly identifies actual malicious activity — the detection matches reality, which is exactly what happened here.
Question 2 of 12 · Security Monitoring
An analyst pulls a record showing 10.1.1.5:52344 talked to 203.0.113.9:443, exchanged 45KB total, and the conversation lasted 12 seconds — but no packet payload or file contents are available. Which data type is this?
Session data (e.g., NetFlow) summarizes a conversation between two hosts — IPs, ports, byte/packet counts, duration — without capturing payload content. This is a core CBROPS data-type distinction.
Question 3 of 12 · Host-Based Analysis
A SOC analyst receives a suspicious executable email attachment. Before allowing it to run on any production endpoint, the analyst wants to detonate the file in an isolated environment to observe its behavior, such as file system changes and network beaconing, without risking the production network. Which endpoint security technology BEST accomplishes this?
Sandboxing executes untrusted files in an isolated environment specifically to observe and analyze their runtime behavior before deciding whether they are malicious.
Question 4 of 12 · Network Intrusion Analysis
An IDS signature designed to detect exploitation of a specific unpatched web server vulnerability fires an alert against a host on the DMZ. Upon investigation, the analyst confirms the destination host is running a fully patched, different web server product that was never vulnerable to this exploit, and no compromise occurred. How should this alert be classified?
The IDS generated an alert (a positive result) for traffic that did not actually represent a successful or applicable attack against the target, making this a false positive — the alert fired but there was no real malicious impact on this host.
Question 5 of 12 · Security Policies and Procedures
A SOC analyst detects ransomware encrypting files on a finance server. The team immediately disconnects the server from the network switch port and disables its VLAN access to stop the ransomware from spreading to other hosts, without yet removing the malware itself. According to the NIST 800-61 incident response lifecycle, which phase does this action represent?
Isolating the affected host to stop lateral spread of an active threat, without yet removing the malware or restoring service, is the definition of the Containment phase in NIST 800-61.
Question 6 of 12 · Security Concepts
A vulnerability scan returns a CVSS v3.1 Base Score of 9.8 for a newly discovered flaw in a web application. According to the standard CVSS qualitative severity rating scale, how should this vulnerability be rated?
Per the CVSS v3.1 qualitative rating scale, scores from 9.0 to 10.0 are rated Critical, and 9.8 falls squarely in that range.
Question 7 of 12 · Security Monitoring
A SOC monitors traffic between an internal host and an external server. NetFlow shows the connection exists on port 443, but the security team cannot inspect the HTTP headers, URLs, or content exchanged during the session. What is primarily responsible for this loss of visibility?
TLS/SSL encryption on port 443 encrypts the payload, hiding HTTP headers, URLs, and content from network-based inspection tools unless TLS decryption/interception is in place. CBROPS explicitly tests encryption's impact on visibility.
Question 8 of 12 · Host-Based Analysis
An analyst investigating a Windows workstation compromise needs to determine which user account successfully authenticated interactively at the console immediately before suspicious PowerShell activity began. Which Windows Security log Event ID should the analyst search for?
Event ID 4624 logs a successful account logon, which is exactly what the analyst needs to confirm which account successfully authenticated at the console.
Question 9 of 12 · Network Intrusion Analysis
While reviewing a packet capture, an analyst wants to isolate all packets belonging to a single conversation flow between two endpoints. Which set of fields makes up the 5-tuple typically used to identify and isolate a specific flow?
The standard 5-tuple used to define and isolate a unique network flow is source IP address, destination IP address, source port, destination port, and protocol (e.g., TCP or UDP). Filtering a capture on these five values uniquely identifies a conversation.
Question 10 of 12 · Security Policies and Procedures
Two weeks after a data breach has been fully remediated, the incident response team holds a meeting to document what went wrong, update the incident response playbook, and recommend new detection rules. Which NIST 800-61 phase does this activity belong to?
Post-Incident Activity (often called 'lessons learned') is the NIST 800-61 phase where the team reviews the response, documents findings, and updates procedures/playbooks based on the incident.
Question 11 of 12 · Security Concepts
A threat hunter notices a process on an endpoint attempting to disable Windows Defender and escalate privileges through an unusual registry modification, but no known malware hash or signature has matched yet. Which term BEST describes this observed suspicious behavior?
An IOA focuses on the behavior and intent of an attack in progress — such as privilege escalation attempts — rather than static artifacts, allowing detection before a full compromise is confirmed.
Question 12 of 12 · Security Monitoring
An analyst needs to confirm whether a specific file download completed successfully, including the HTTP status code returned and the file size transferred, without capturing full packet payloads. Which data type should the analyst use?
Transaction data records the details of a completed application-layer exchange (e.g., HTTP request/response pairs, status codes, file transfer outcomes) — exactly what's needed to confirm download success without full PCAP.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.
The exam fee is approximately $300 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 5 domains: Security Concepts (20%), Security Monitoring (25%), Host-Based Analysis (20%), Network Intrusion Analysis (20%), Security Policies and Procedures (15%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.