Free CompTIA SecurityX practice — 6 questions on Security Operations, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Security Operations
An incident responder arrives at a compromised production database server. Business SLA requires the server be returned to service within 15 minutes. Given this extreme time constraint, which action should be prioritized to preserve the MOST volatile evidence before the system is taken down or rebooted?
Per the order of volatility, RAM contents, running processes, and active network connections are the most perishable evidence and are lost immediately on shutdown or reboot. With only 15 minutes available, capturing memory and network state first maximizes evidentiary value before the server is restored to service.
Question 2 of 6 · Security Operations
A SOC is experiencing analyst fatigue from a high volume of phishing alerts. Leadership wants to speed up response using SOAR automation but is concerned that fully automated remediation could disrupt production systems if the verdict is wrong. Which playbook design BEST balances automation speed with appropriate human oversight?
Threshold-based routing lets the SOAR platform automatically contain high-confidence, low-risk findings while preserving human-in-the-loop approval for actions that carry business disruption risk — this is the standard enterprise pattern for balancing speed with safety in orchestration.
Question 3 of 6 · Security Operations
A threat intel feed delivers a STIX indicator tagged 'APT29' with a confidence score of 15 out of 100. The analyst wants to make productive use of this low-confidence indicator without generating excessive false positives across the enterprise. Which action is MOST appropriate?
Low-confidence indicators still have hunting value when correlated with other telemetry. Using them in a passive watchlist for threat hunting extracts intelligence value without the false-positive risk of automated enforcement actions based on unreliable data.
Question 4 of 6 · Security Operations
During an enterprise forensic investigation, an analyst suspects an attacker used anti-forensic techniques to falsify file timestamps (timestomping) on a Windows host to hide the true timeline of compromise. Which technique is MOST effective for detecting this manipulation?
Timestomping tools typically modify the $STANDARD_INFORMATION timestamps visible in the MFT but cannot easily alter journal records like $LogFile and $UsnJrnl, which independently log filesystem transactions. Discrepancies between these artifacts are the classic forensic indicator of timestamp manipulation.
Question 5 of 6 · Security Operations
A security team discovers that an attacker crafted network traffic with subtle perturbations specifically designed to evade a machine-learning-based NIDS by pushing the classifier's confidence score just below the alerting threshold (an adversarial evasion attack). Which operational control BEST mitigates this class of risk going forward?
Adversarial examples are typically crafted against a specific model's decision boundary. A diverse ensemble of heterogeneous detection methods (different ML architectures plus behavioral/signature detection) greatly reduces the chance that one crafted evasion technique defeats every layer simultaneously — this is the recommended defense-in-depth approach for ML-based detection.
Question 6 of 6 · Security Operations
A UEBA platform flagged a privileged admin account performing an unusual bulk data export at 3 AM, which deviates sharply from the account's behavioral baseline. However, the SIEM automatically suppressed the alert because the source IP matched a 'known VPN' allowlist. What is the BEST enterprise-scale fix to prevent this blind spot while keeping false positives low elsewhere?
Risk-based scoring that treats allowlist membership as one weighted factor — rather than an absolute suppression rule — allows strong behavioral anomalies (like an atypical 3 AM bulk export by a privileged account) to still surface even from a trusted IP, closing the blind spot without discarding the useful noise-reduction the allowlist provides for benign traffic.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code FREETEST33 — valid through Oct 6.