skip to content

Security Operations & Incident Response

The defender's operating rhythm: how a SOC turns raw logs into detections, runs incidents through a disciplined lifecycle, hunts proactively, consumes threat intel, and preserves evidence that holds up. This is the conceptual core of SOC-analyst and blue-team interviews.

on this pageshow

explore

questions

419 · 10 sections

Why does a SOC audit its own analysts' SIEM search queries?

level: juniorimportance: must knowfreq 58%
basics
~20 s

Reading employee telemetry is itself a privileged act. The query audit records who searched which identifier, when, and under which case reference, so analyst misuse is detectable and the SOC's own access to people's data is evidenced.

open as a page

With 90-day SIEM retention, a partner reports an intrusion seven months old — what can you no longer answer?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Anything about months four to seven. When access began, how it was obtained, and what it touched back then are unsearchable. You can describe only the last 90 days, and an empty result outside the window proves nothing.

open as a page

What is the difference between a log record's event time and its ingest time in a SIEM?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Event time is when the source says the activity happened; ingest time is when your collector received the record. Event time answers when it happened, ingest time answers the earliest moment the SOC could have known about it.

open as a page

In SOC log-source coverage, what is the difference between an enrolled host and a reporting host?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Enrolled means a host is registered in the collection console, which is a configuration fact. Reporting means its events actually arrived in the SIEM inside a recent window, which is an observed fact. Count coverage from arrivals.

open as a page

Why normalise vendor logs onto a shared schema like OCSF or ECS?

level: juniorimportance: must knowfreq 62%
basics
~10 s

A shared schema gives every product one field name for the same idea, so a single detection, search or pivot works across all feeds instead of being rewritten once per vendor dialect.

open as a page

In a SIEM correlation rule requiring event A then event B, what does the time window control, and what does widening it cost?

level: juniorimportance: must knowfreq 68%
basics
~20 s

The window is the largest event-time gap the rule will join two stages across; outside it the pair is never matched. Too short misses a patient sequence; too long joins unrelated events, raising false alarms and the state held.

open as a page

In Splunk SPL, why can a hunt search with no index or time bounds report a false 'nothing found'?

level: juniorimportance: must knowfreq 68%
basics
~20 s

An unbounded search can be finalized or truncated before it reads everything, so an empty result proves only that the search stopped early, not that nothing happened. Pin the index and the time range in the base search.

open as a page

In a first-seen detection, what does 'first seen' actually assert about the value it fired on?

level: juniorimportance: must knowfreq 62%
basics
~10 s

Only that this value never appeared in the rule's lookback window for that entity. It is a claim about your recorded history, not evidence that the value is malicious or even genuinely new.

open as a page

Before writing a detection rule, what must be true of your telemetry for an adversary behaviour to be detectable?

level: juniorimportance: must knowfreq 72%
basics
~20 s

A record the estate actually writes must carry at least one field whose value differs between the behaviour and the same action done legitimately. With no separating field, no rule can match it, however the rule is written.

open as a page

Why does a detection rule declare the log source and fields it needs, not just the search?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A rule only works if the records it queries exist and carry those fields. Declaring the source and field names makes that assumption checkable before deployment; a rule over missing data returns nothing and looks exactly like a quiet estate.

open as a page

A data-loss policy can match on a regex pattern, a document fingerprint or a sensitivity label - what does each detect?

level: juniorimportance: must knowfreq 72%
basics
~20 s

A pattern rule matches content shaped like sensitive data, so it also fires on lookalikes. A fingerprint matches content that resembles a specific indexed document or record set. A label matches metadata someone attached at creation, not the content at all.

open as a page

A UEBA console shows a user risk score of 92 - what does that number actually represent?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A UEBA risk score is the sum of weighted reasons that fired on one account in a time window, measured against a learned baseline. It orders the queue; it is not a probability that the user is malicious.

open as a page

What does click-time URL rewriting in a mail gateway catch that delivery-time scanning cannot?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A link that is harmless when the message arrives and armed hours later. Delivery-time scanning judges the destination as it was at delivery; rewriting routes every click through the gateway, so the destination is judged again at click time.

open as a page

What does an EDR verdict of 'clean, signed binary' actually prove about a process?

level: juniorimportance: must knowfreq 74%
basics
~20 s

Only two narrow things: the file chains to a trusted publisher certificate and is unmodified since signing, and no rule in that one product matched the telemetry the agent collected. Neither claim is about the process's behaviour.

open as a page

Why do hash and YARA matching miss a signed archiving tool encrypting a file share?

level: juniorimportance: must knowfreq 74%
basics
~20 s

Hash and YARA matching test content against known-bad patterns. A signed, allow-listed archiver is legitimate content, so nothing matches. The malice lives in how the tool is driven, and only a behavioural chain can convict that.

open as a page

A flagged Kubernetes pod was deleted and replaced before anyone captured it - what is gone for good?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Everything that existed only inside that container: the process memory holding a memory-only loader, its live network and process state, and the writable layer's dropped files. Shipped logs survive, but they record what was emitted, never the code that ran.

open as a page

In a breach determination, what is the difference between personal data being exposed and being accessed?

level: juniorimportance: must knowfreq 57%
basics
~20 s

Exposure means the data became reachable because a control failed. Access means someone actually retrieved it. Notification duties turn on access or its reasonable likelihood, so an investigator looks for a retrieval record, not merely an opportunity.

open as a page

What makes a communications channel genuinely out-of-band during a suspected intrusion?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Out-of-band means the channel shares no dependency with the systems under investigation: different transport, different identity provider, different devices, and a member list not drawn from the compromised directory. A second app behind the same sign-on is still in-band.

open as a page

What does an EDR's network-isolate action on a compromised host stop, and what does it not stop?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Network isolation cuts a host's traffic except the EDR agent's own channel, so an intruder loses interactive access from that machine. It kills no running process, removes no persistence, revokes no stolen credential, and touches nothing on any other host.

open as a page

Why is deleting the implant from the one server that alerted not eradication?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Because eradication targets the intruder's whole foothold, not one file. They may hold persistence on other hosts, valid credentials taken from yours, and the same unfixed way in. Deleting an implant removes an artefact, not their access.

open as a page

Why can't a 1.8-million-indicator threat feed be pushed straight into a proxy block list?

level: juniorimportance: must knowfreq 55%
basics
~20 s

Every entry costs something to evaluate and something to be wrong about. Enforcement lists have size and push limits, and adversary infrastructure usually sits on shared or CDN-fronted addresses that also carry your own business traffic.

open as a page

An alert is enriched with a commercial threat-feed hit on a domain - what does that hit prove?

level: juniorimportance: must knowfreq 66%
basics
~20 s

It proves only that some curation process put that domain on a list at some point. It says nothing about what your host actually did. Treat a feed hit as one weighted input to a verdict, never as the verdict.

open as a page

Why run a newly published C2 domain back through five months of historic DNS logs?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Because indicators arrive late. A block added today only matches traffic from today onward; the intrusion the indicator describes may already be months old in your stored logs. The retro sweep is the only way to see backwards.

open as a page

When researching a suspected C2 domain, what is the difference between passive and active collection?

level: juniorimportance: must knowfreq 64%
basics
~20 s

Passive collection reads records third parties already hold - passive DNS, certificate transparency, WHOIS history, stored scan data - so nothing reaches the adversary. Active collection resolves or connects to his host and writes a footprint into logs he controls.

open as a page

What must a priority intelligence requirement name that 'keep an eye on infostealer activity' does not?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A priority intelligence requirement names a consumer, the decision they owe by a date, and what would count as an answer. 'Keep an eye on infostealer activity' names none of those, so nobody acts on it and it never closes.

open as a page

A threat hunt across your ESXi hosts returns no hits — what does that negative result establish?

level: juniorimportance: must knowfreq 56%
basics
~20 s

A negative hunt establishes only that the logic you ran, over the telemetry you held, for the hosts that were reporting, in the window retained, matched nothing. It is a statement about the search, not proof the estate is clean.

open as a page

Your hunt finds suspicious activity that no detection rule ever alerted on. Does that make it less likely to be malicious?

level: juniorimportance: must knowfreq 55%
basics
~10 s

No. A rule set only covers behaviour someone wrote a rule for, over sources someone connected. Silence measures your detection coverage, not the activity's intent. Judge the behaviour on its own evidence.

open as a page

What must a hunt query gain before it can run unattended as a detection rule?

level: juniorimportance: must knowfreq 62%
basics
~20 s

It has to stand without its author: logic narrowed from browse-everything to one defensible claim, an explicit threshold and evaluation window, a named owner who answers when it misfires, and triage notes saying what benign matches look like and what the analyst does next.

open as a page

What makes a threat-hunting hypothesis falsifiable, and why does 'are we breached?' fail?

level: juniorimportance: must knowfreq 72%
basics
~20 s

A falsifiable hunting hypothesis names one adversary behaviour, the telemetry where that behaviour would leave a record, and the result that would kill it. 'Are we breached?' names no behaviour and no observation, so no query can end it.

open as a page

When does a worry about intruder-installed remote-access tools become a hunt, a rule, or a ticket?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Route by cost. A hunt is a one-off, time-boxed search that answers the question once. A standing rule creates triage work on every match forever, so it needs recurrence, precision and an owner. A ticket is for when only remediation is left.

open as a page

What does the hash you record when imaging a suspect disk actually prove?

level: juniorimportance: must knowfreq 78%
basics
~20 s

It proves the image is a bit-for-bit copy of what the drive returned at capture, and has not drifted since. It says nothing about who wrote the data, when, or what happened before you arrived.

open as a page

What can a live capture of a running host give you that an offline disk image cannot?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Only a running host still holds decryption keys, decrypted mounted volumes, running processes and network state in memory. Power it off and an image of the same disk is ciphertext, or silent, for all of it.

open as a page

What is a forensic triage artefact set, and how does it differ from a full disk image?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A triage artefact set copies a chosen list of high-value host artefacts - event logs, execution and persistence records, scheduled tasks - instead of every sector of the disk. Minutes and megabytes per host rather than hours and terabytes, so it scales to hundreds of machines.

open as a page

What does the order of volatility rank on a compromised host, and why does it set capture order?

level: juniorimportance: must knowfreq 74%
basics
~20 s

It ranks evidence by how fast it disappears, not by how useful it is. CPU registers and cache decay first, then RAM, then network state such as socket and ARP tables, then disk, then archived logs. Collect shortest-lived first.

open as a page

You collect a backdoored vendor installer from an infected host — what must each chain-of-custody entry record?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Each entry names the item by a unique identifier, the date and time of the move, who released it, who received it, why it moved and where it went, signed by both parties. The point is that the item is never unaccounted for.

open as a page

What must a security alert's case note record beyond the verdict, so another analyst can act on it?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A case note must let someone else reach the same verdict without you: the exact queries run with their time windows, what was found and what was ruled out, every timestamp in UTC, and the reasoning behind the disposition.

open as a page

When closing a security alert, what separates a false positive from a benign true positive?

level: juniorimportance: must knowfreq 72%
basics
~20 s

A false positive means the detection was wrong: the behaviour it claimed to see did not occur. A benign true positive means the detection was right and the behaviour was authorised. One indicts the rule; the other clears it.

open as a page

What must a false-positive closure record carry for the detection engineer who owns the rule?

level: juniorimportance: must knowfreq 60%
basics
~20 s

The rule and the version that fired, the exact field and value that made the activity benign, the asset and its asset group, and the analyst's reason. A verdict label on its own is not evidence anyone can act on.

open as a page

What does a CMDB asset criticality and owner lookup tell you about whether an alert is malicious?

level: juniorimportance: must knowfreq 74%
basics
~20 s

Nothing. Criticality and owner tell you what is at stake and who to ask, so they change urgency, routing and the response you may take. Only evidence about the behaviour itself moves a malicious-or-not verdict.

open as a page

A certutil download command alerts on a packaging workstation and turns out to be authorised: false positive or benign true positive?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A benign true positive. The behaviour really happened and the rule matched exactly what it was written to match; it was simply authorised. A false positive is a rule firing on activity that never matched its intent at all.

open as a page

In a purple-team session, why re-run the technique after the detection engineer edits the rule?

level: juniorimportance: must knowfreq 62%
basics
~10 s

Because an edited rule is only a hypothesis until the behaviour it targets is performed again while it is live. Re-execution proves the whole path, from event delivery to a routed alert, actually works.

open as a page

Why doesn't replaying saved log records prove a detection still works after a sensor upgrade?

level: juniorimportance: must knowfreq 58%
basics
~20 s

Replaying saved records tests only the stages after collection: parsing and rule logic. It cannot show that the upgraded sensor still emits that event with the same fields, or that the forwarder still ships it. Only re-executing the real technique exercises the whole path.

open as a page

In a red-team engagement, what is a deconfliction contact and what question do they exist to answer?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A named, reachable person on each side of the exercise whose job is to answer one question fast: is this specific activity ours? They attribute or disown observed behaviour. They do not authorise it and they do not order a stand-down.

open as a page

A vulnerability scan, a pentest and a red team engagement all test security — what does each actually prove?

level: juniorimportance: must knowfreq 76%
basics
~20 s

A scan proves a weakness is present. A pentest proves an operator could exploit it and how far the chain reaches. A red team proves whether your defenders detect and stop a realistic path to an objective.

open as a page

Why derive an emulation technique set from a threat profile rather than a popularity list?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A popularity list tests the techniques other organisations happen to report; a threat profile tests the ones the adversary interested in you actually uses. Only the second supports a claim about the intrusion you are likely to face.

open as a page

Your SOC's busiest detection rule fired 40,000 times last quarter - what does that count tell you about its value?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A firing count measures how often a pattern occurs in the estate, not how often it means an intrusion. Value comes from yield: the share of firings that became real, escalated cases. The busiest rule can yield zero.

open as a page

A technique cell on your ATT&CK coverage heatmap is green - what three different claims could that colour be making?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Green usually stands for one of three very different facts: the log source that would show the behaviour is collected, a detection rule exists over that data, or the behaviour was actually executed and the rule caught it.

open as a page

Why can a SOC measure its false-positive rate but not its false-negative rate?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Every alert that fires gets a verdict, so false positives are countable. An intrusion nobody detected leaves no case and no verdict, so a miss rate has neither a numerator nor a denominator you can read out of SOC data.

open as a page

In SOC outcome reporting, what events start and stop the MTTD and MTTC clocks?

level: juniorimportance: must knowfreq 72%
basics
~20 s

MTTD runs from the adversary's first malicious action to the moment your organisation knows it is compromised. MTTC runs from that same moment to containment actually executed. Dwell time is the MTTD span measured on one intrusion.

open as a page

What does 'zero security incidents this quarter' actually prove about your estate?

level: juniorimportance: must knowfreq 52%
basics
~20 s

It proves only that nothing was detected, worked and declared. Zero is consistent with a genuinely quiet estate and with an intrusion nobody saw. The number on its own cannot tell you which one you had.

open as a page