Security Operations & Incident Response
The defender's operating rhythm: how a SOC turns raw logs into detections, runs incidents through a disciplined lifecycle, hunts proactively, consumes threat intel, and preserves evidence that holds up. This is the conceptual core of SOC-analyst and blue-team interviews.
on this pageshowhide
explore
- Telemetry & Log Sources45 questions
- Evidence at the Source21 questions
- Surviving the Trip12 questions
- Limits of the Record12 questions
- SIEM & Detection Engineering39 questions
- From Behaviour to Signal16 questions
- Expressing the Logic11 questions
- After It Ships12 questions
- EDR, SOAR & Defensive Tooling Classes44 questions
- What the Sensor Records16 questions
- Controls That Decide Alone16 questions
- Acting Without You12 questions
- Incident Response Lifecycle60 questions
- Declaring an Intrusion24 questions
- Cutting The Adversary Out20 questions
- Answering For It16 questions
- Threat Intelligence & OSINT36 questions
- Producing Intel12 questions
- Structuring & Exchange12 questions
- From Feed to Decision12 questions
- Threat Hunting39 questions
- Framing The Question11 questions
- Finding The Abnormal16 questions
- Banking The Result12 questions
- Digital Forensics Fundamentals47 questions
- Acquiring Before It Vanishes15 questions
- Reading The Artefacts20 questions
- Evidence That Holds Up12 questions
- Alert Triage & Investigation44 questions
- First Verdict20 questions
- Widening the Picture12 questions
- Disposition and Feedback12 questions
- Adversary Emulation36 questions
- Designing the Exercise12 questions
- Against Live Defences12 questions
- Turning Results Into Coverage12 questions
- Measuring Detection & Response29 questions
- Outcome Metrics8 questions
- Defensible Coverage Claims13 questions
- Acting on the Numbers8 questions
questions
419 · 10 sectionsWhy does a SOC audit its own analysts' SIEM search queries?
basics
~20 sReading employee telemetry is itself a privileged act. The query audit records who searched which identifier, when, and under which case reference, so analyst misuse is detectable and the SOC's own access to people's data is evidenced.
With 90-day SIEM retention, a partner reports an intrusion seven months old — what can you no longer answer?
basics
~20 sAnything about months four to seven. When access began, how it was obtained, and what it touched back then are unsearchable. You can describe only the last 90 days, and an empty result outside the window proves nothing.
What is the difference between a log record's event time and its ingest time in a SIEM?
basics
~20 sEvent time is when the source says the activity happened; ingest time is when your collector received the record. Event time answers when it happened, ingest time answers the earliest moment the SOC could have known about it.
In SOC log-source coverage, what is the difference between an enrolled host and a reporting host?
basics
~20 sEnrolled means a host is registered in the collection console, which is a configuration fact. Reporting means its events actually arrived in the SIEM inside a recent window, which is an observed fact. Count coverage from arrivals.
Why normalise vendor logs onto a shared schema like OCSF or ECS?
basics
~10 sA shared schema gives every product one field name for the same idea, so a single detection, search or pivot works across all feeds instead of being rewritten once per vendor dialect.
In a SIEM correlation rule requiring event A then event B, what does the time window control, and what does widening it cost?
basics
~20 sThe window is the largest event-time gap the rule will join two stages across; outside it the pair is never matched. Too short misses a patient sequence; too long joins unrelated events, raising false alarms and the state held.
In Splunk SPL, why can a hunt search with no index or time bounds report a false 'nothing found'?
basics
~20 sAn unbounded search can be finalized or truncated before it reads everything, so an empty result proves only that the search stopped early, not that nothing happened. Pin the index and the time range in the base search.
In a first-seen detection, what does 'first seen' actually assert about the value it fired on?
basics
~10 sOnly that this value never appeared in the rule's lookback window for that entity. It is a claim about your recorded history, not evidence that the value is malicious or even genuinely new.
Before writing a detection rule, what must be true of your telemetry for an adversary behaviour to be detectable?
basics
~20 sA record the estate actually writes must carry at least one field whose value differs between the behaviour and the same action done legitimately. With no separating field, no rule can match it, however the rule is written.
Why does a detection rule declare the log source and fields it needs, not just the search?
basics
~20 sA rule only works if the records it queries exist and carry those fields. Declaring the source and field names makes that assumption checkable before deployment; a rule over missing data returns nothing and looks exactly like a quiet estate.
A data-loss policy can match on a regex pattern, a document fingerprint or a sensitivity label - what does each detect?
basics
~20 sA pattern rule matches content shaped like sensitive data, so it also fires on lookalikes. A fingerprint matches content that resembles a specific indexed document or record set. A label matches metadata someone attached at creation, not the content at all.
A UEBA console shows a user risk score of 92 - what does that number actually represent?
basics
~20 sA UEBA risk score is the sum of weighted reasons that fired on one account in a time window, measured against a learned baseline. It orders the queue; it is not a probability that the user is malicious.
What does click-time URL rewriting in a mail gateway catch that delivery-time scanning cannot?
basics
~20 sA link that is harmless when the message arrives and armed hours later. Delivery-time scanning judges the destination as it was at delivery; rewriting routes every click through the gateway, so the destination is judged again at click time.
What does an EDR verdict of 'clean, signed binary' actually prove about a process?
basics
~20 sOnly two narrow things: the file chains to a trusted publisher certificate and is unmodified since signing, and no rule in that one product matched the telemetry the agent collected. Neither claim is about the process's behaviour.
Why do hash and YARA matching miss a signed archiving tool encrypting a file share?
basics
~20 sHash and YARA matching test content against known-bad patterns. A signed, allow-listed archiver is legitimate content, so nothing matches. The malice lives in how the tool is driven, and only a behavioural chain can convict that.
A flagged Kubernetes pod was deleted and replaced before anyone captured it - what is gone for good?
basics
~20 sEverything that existed only inside that container: the process memory holding a memory-only loader, its live network and process state, and the writable layer's dropped files. Shipped logs survive, but they record what was emitted, never the code that ran.
In a breach determination, what is the difference between personal data being exposed and being accessed?
basics
~20 sExposure means the data became reachable because a control failed. Access means someone actually retrieved it. Notification duties turn on access or its reasonable likelihood, so an investigator looks for a retrieval record, not merely an opportunity.
What makes a communications channel genuinely out-of-band during a suspected intrusion?
basics
~20 sOut-of-band means the channel shares no dependency with the systems under investigation: different transport, different identity provider, different devices, and a member list not drawn from the compromised directory. A second app behind the same sign-on is still in-band.
What does an EDR's network-isolate action on a compromised host stop, and what does it not stop?
basics
~20 sNetwork isolation cuts a host's traffic except the EDR agent's own channel, so an intruder loses interactive access from that machine. It kills no running process, removes no persistence, revokes no stolen credential, and touches nothing on any other host.
Why is deleting the implant from the one server that alerted not eradication?
basics
~20 sBecause eradication targets the intruder's whole foothold, not one file. They may hold persistence on other hosts, valid credentials taken from yours, and the same unfixed way in. Deleting an implant removes an artefact, not their access.
Why can't a 1.8-million-indicator threat feed be pushed straight into a proxy block list?
basics
~20 sEvery entry costs something to evaluate and something to be wrong about. Enforcement lists have size and push limits, and adversary infrastructure usually sits on shared or CDN-fronted addresses that also carry your own business traffic.
An alert is enriched with a commercial threat-feed hit on a domain - what does that hit prove?
basics
~20 sIt proves only that some curation process put that domain on a list at some point. It says nothing about what your host actually did. Treat a feed hit as one weighted input to a verdict, never as the verdict.
Why run a newly published C2 domain back through five months of historic DNS logs?
basics
~20 sBecause indicators arrive late. A block added today only matches traffic from today onward; the intrusion the indicator describes may already be months old in your stored logs. The retro sweep is the only way to see backwards.
When researching a suspected C2 domain, what is the difference between passive and active collection?
basics
~20 sPassive collection reads records third parties already hold - passive DNS, certificate transparency, WHOIS history, stored scan data - so nothing reaches the adversary. Active collection resolves or connects to his host and writes a footprint into logs he controls.
What must a priority intelligence requirement name that 'keep an eye on infostealer activity' does not?
basics
~20 sA priority intelligence requirement names a consumer, the decision they owe by a date, and what would count as an answer. 'Keep an eye on infostealer activity' names none of those, so nobody acts on it and it never closes.
A threat hunt across your ESXi hosts returns no hits — what does that negative result establish?
basics
~20 sA negative hunt establishes only that the logic you ran, over the telemetry you held, for the hosts that were reporting, in the window retained, matched nothing. It is a statement about the search, not proof the estate is clean.
Your hunt finds suspicious activity that no detection rule ever alerted on. Does that make it less likely to be malicious?
basics
~10 sNo. A rule set only covers behaviour someone wrote a rule for, over sources someone connected. Silence measures your detection coverage, not the activity's intent. Judge the behaviour on its own evidence.
What must a hunt query gain before it can run unattended as a detection rule?
basics
~20 sIt has to stand without its author: logic narrowed from browse-everything to one defensible claim, an explicit threshold and evaluation window, a named owner who answers when it misfires, and triage notes saying what benign matches look like and what the analyst does next.
What makes a threat-hunting hypothesis falsifiable, and why does 'are we breached?' fail?
basics
~20 sA falsifiable hunting hypothesis names one adversary behaviour, the telemetry where that behaviour would leave a record, and the result that would kill it. 'Are we breached?' names no behaviour and no observation, so no query can end it.
When does a worry about intruder-installed remote-access tools become a hunt, a rule, or a ticket?
basics
~20 sRoute by cost. A hunt is a one-off, time-boxed search that answers the question once. A standing rule creates triage work on every match forever, so it needs recurrence, precision and an owner. A ticket is for when only remediation is left.
What does the hash you record when imaging a suspect disk actually prove?
basics
~20 sIt proves the image is a bit-for-bit copy of what the drive returned at capture, and has not drifted since. It says nothing about who wrote the data, when, or what happened before you arrived.
What can a live capture of a running host give you that an offline disk image cannot?
basics
~20 sOnly a running host still holds decryption keys, decrypted mounted volumes, running processes and network state in memory. Power it off and an image of the same disk is ciphertext, or silent, for all of it.
What is a forensic triage artefact set, and how does it differ from a full disk image?
basics
~20 sA triage artefact set copies a chosen list of high-value host artefacts - event logs, execution and persistence records, scheduled tasks - instead of every sector of the disk. Minutes and megabytes per host rather than hours and terabytes, so it scales to hundreds of machines.
What does the order of volatility rank on a compromised host, and why does it set capture order?
basics
~20 sIt ranks evidence by how fast it disappears, not by how useful it is. CPU registers and cache decay first, then RAM, then network state such as socket and ARP tables, then disk, then archived logs. Collect shortest-lived first.
You collect a backdoored vendor installer from an infected host — what must each chain-of-custody entry record?
basics
~20 sEach entry names the item by a unique identifier, the date and time of the move, who released it, who received it, why it moved and where it went, signed by both parties. The point is that the item is never unaccounted for.
What must a security alert's case note record beyond the verdict, so another analyst can act on it?
basics
~20 sA case note must let someone else reach the same verdict without you: the exact queries run with their time windows, what was found and what was ruled out, every timestamp in UTC, and the reasoning behind the disposition.
When closing a security alert, what separates a false positive from a benign true positive?
basics
~20 sA false positive means the detection was wrong: the behaviour it claimed to see did not occur. A benign true positive means the detection was right and the behaviour was authorised. One indicts the rule; the other clears it.
What must a false-positive closure record carry for the detection engineer who owns the rule?
basics
~20 sThe rule and the version that fired, the exact field and value that made the activity benign, the asset and its asset group, and the analyst's reason. A verdict label on its own is not evidence anyone can act on.
What does a CMDB asset criticality and owner lookup tell you about whether an alert is malicious?
basics
~20 sNothing. Criticality and owner tell you what is at stake and who to ask, so they change urgency, routing and the response you may take. Only evidence about the behaviour itself moves a malicious-or-not verdict.
A certutil download command alerts on a packaging workstation and turns out to be authorised: false positive or benign true positive?
basics
~20 sA benign true positive. The behaviour really happened and the rule matched exactly what it was written to match; it was simply authorised. A false positive is a rule firing on activity that never matched its intent at all.
In a purple-team session, why re-run the technique after the detection engineer edits the rule?
basics
~10 sBecause an edited rule is only a hypothesis until the behaviour it targets is performed again while it is live. Re-execution proves the whole path, from event delivery to a routed alert, actually works.
Why doesn't replaying saved log records prove a detection still works after a sensor upgrade?
basics
~20 sReplaying saved records tests only the stages after collection: parsing and rule logic. It cannot show that the upgraded sensor still emits that event with the same fields, or that the forwarder still ships it. Only re-executing the real technique exercises the whole path.
In a red-team engagement, what is a deconfliction contact and what question do they exist to answer?
basics
~20 sA named, reachable person on each side of the exercise whose job is to answer one question fast: is this specific activity ours? They attribute or disown observed behaviour. They do not authorise it and they do not order a stand-down.
A vulnerability scan, a pentest and a red team engagement all test security — what does each actually prove?
basics
~20 sA scan proves a weakness is present. A pentest proves an operator could exploit it and how far the chain reaches. A red team proves whether your defenders detect and stop a realistic path to an objective.
Why derive an emulation technique set from a threat profile rather than a popularity list?
basics
~20 sA popularity list tests the techniques other organisations happen to report; a threat profile tests the ones the adversary interested in you actually uses. Only the second supports a claim about the intrusion you are likely to face.
Your SOC's busiest detection rule fired 40,000 times last quarter - what does that count tell you about its value?
basics
~20 sA firing count measures how often a pattern occurs in the estate, not how often it means an intrusion. Value comes from yield: the share of firings that became real, escalated cases. The busiest rule can yield zero.
A technique cell on your ATT&CK coverage heatmap is green - what three different claims could that colour be making?
basics
~20 sGreen usually stands for one of three very different facts: the log source that would show the behaviour is collected, a detection rule exists over that data, or the behaviour was actually executed and the rule caught it.
Why can a SOC measure its false-positive rate but not its false-negative rate?
basics
~20 sEvery alert that fires gets a verdict, so false positives are countable. An intrusion nobody detected leaves no case and no verdict, so a miss rate has neither a numerator nor a denominator you can read out of SOC data.
In SOC outcome reporting, what events start and stop the MTTD and MTTC clocks?
basics
~20 sMTTD runs from the adversary's first malicious action to the moment your organisation knows it is compromised. MTTC runs from that same moment to containment actually executed. Dwell time is the MTTD span measured on one intrusion.
What does 'zero security incidents this quarter' actually prove about your estate?
basics
~20 sIt proves only that nothing was detected, worked and declared. Zero is consistent with a genuinely quiet estate and with an intrusion nobody saw. The number on its own cannot tell you which one you had.