skip to content

Limits of the Record

Three things decide whether a search answers anything: whether the timestamps agree, whether the data reaches back far enough, and whether you may read it. Interviewers find people who assume yes.

on this pageshow

explore

questions

12

Why does a SOC audit its own analysts' SIEM search queries?

level: juniorimportance: must knowfreq 58%

answer

  1. The search bar is a privilege
  2. Analysts are a monitored population too
  3. Who searched which identifier, when
  4. The case reference supplies the purpose
  5. Stored where analysts cannot edit it

basics

~20 s

Reading employee telemetry is itself a privileged act. The query audit records who searched which identifier, when, and under which case reference, so analyst misuse is detectable and the SOC's own access to people's data is evidenced.

solid answer

~40 s

A SOC's search bar reaches mailboxes, endpoints, sign-ins and web history for named people, so running a query exercises privilege the way an admin login does. The query audit is the control over it: for every search it records the account, the timestamp, the index, the query text, the time range and the case reference the search ran under. That buys deterrence and detection of misuse — the analyst looking up an ex-partner, a colleague or an executive is a real, recurring pattern; defensibility, so an employee or representative asking who read their data gets evidence; and protection for the analyst, since a query tied to an open case shows they were working. The audit must live where SOC staff cannot edit it, and be reviewed outside the SOC's reporting line.

code

json · 10 lines
json
{
  "event": "search.executed",
  "time": "2026-03-11T02:41:07Z",
  "actor": "analyst.jdoe",
  "index": "mail_audit",
  "query": "recipient:[email protected] OR sender:[email protected]",
  "time_range": "-90d..now",
  "case_ref": null,
  "results_returned": 412
}

go deeper

for a junior

Be ready to say plainly that running a search over a named employee is a privileged act, and that your own queries are recorded with your account, the identifiers and the case you ran them under.

for a middle

Explain the fields that make the record useful — actor, index, query, time range, case reference — and why a null case reference is the pattern that gets reviewed rather than an automatic finding.

for a senior

Show the failure modes: shared accounts, unaudited export and direct-query paths, and an audit index the SOC itself administers. Say who reviews it and on what cadence.

for a principal

Own the argument that the SOC's access power needs the same accountability it demands of admins, and be able to defend the SOC's record of access to an employee representative or an auditor.

## The SOC as a subject, not only an operator Almost everything else on this topic treats the SOC as the party doing the watching. The query audit inverts that: the analysts themselves become a monitored population, and their searches become a log source like any other. The reason is simply the reach of the tooling. A tier-1 analyst with a normal console can typically pull a named person's mailbox activity, their endpoint process telemetry, their sign-in history, their proxy or DNS records and their file access. That is a more intimate view of an employee's day than their own manager has, it is available in seconds, and it leaves no trace on the subject's side. An organisation that hands out that capability without a record of how it is used has created an unaudited surveillance power. ## What the record contains A usable query-audit entry captures, at minimum: | Field | Why it matters | | --- | --- | | Actor account | Who ran it — and it must be a named human account, not a shared service account | | Timestamp | When, including out-of-hours patterns | | Index or source | Mail audit, endpoint telemetry, sign-in logs, HR data | | Query text | Which identifiers were named | | Time range | A 6-hour window versus 90 days is a completely different intrusion into someone's life | | Case reference | The stated purpose — the field that turns a search into an authorised act | | Result count | Whether anything was returned | The case reference is the important one. Nothing in the query itself supplies a purpose; the link to an open, approved case does. A search with a null case reference is not automatically misconduct, but it is the pattern worth asking about. ## What the record proves, and what it does not A query-audit entry proves that **an account submitted that query at that time**. It does not prove a human was at the keyboard, that the analyst read or understood the results, that the results were exported, or that the purpose was legitimate. It equally does not prove the reverse: an analyst who ran no query may still have seen the data on a dashboard, in an alert payload, or in a screenshot a colleague pasted into a chat. That direction matters when the audit is used as evidence in a disciplinary case. "The account ran a 90-day mailbox search for a named colleague with no case reference" is a defensible, factual claim. "The analyst read their colleague's email" is a stronger claim that the record alone does not carry. ## Detections written over it Because it is just another log source, you can write detections on it. Common ones: - a search naming the analyst's own identifiers (self-lookup); - searches for identifiers with no linked open case; - lookups of a watchlist of executives, board members, HR staff or high-profile employees; - a sudden rise in the number of distinct subjects one analyst queried in a day; - unusually broad time ranges on person-scoped searches; - bulk exports, which frequently escape the audit entirely. These are low-volume and high-consequence, so they are usually reviewed by a person rather than paged. ## The failure modes that make the control fake 1. **Shared accounts.** If four analysts share one console login, the audit names nobody. 2. **Unaudited paths.** An analyst who queries the underlying data store directly, opens a notebook against the raw index, or pulls a CSV export may bypass the audited interface completely. Every read path needs to be audited, or the audited one becomes optional. 3. **The subject administers the audit.** If SOC staff can delete or edit the query-audit index, it cannot be used against them. Ship it to an append-only store outside their administrative control. 4. **Nobody reviews it.** An audit no one reads deters only people who believe someone reads it. Assign the review to a function outside the SOC's line — internal audit, privacy, or compliance. 5. **No case reference field.** Without a purpose binding, every entry looks equally justified and the audit answers no question. ## Why interviewers ask it It is a fast test of whether a candidate sees the SOC as accountable rather than merely trusted. Someone who answers "so we can catch analysts snooping" has half of it; the stronger answer adds that it makes the organisation's *own* access to employee data evidenced, which is what you need when an employee, an employee representative or an auditor asks the question.

  • What detections would you write over the analyst query audit?
    Self-lookups where an analyst names their own identifiers; searches with no linked open case reference; queries naming executives, HR staff or board members from a watchlist; a jump in distinct subjects queried per analyst per day; unusually wide time ranges on a person-scoped search; and bulk exports. Volumes are low and consequences are personal, so these go to a human reviewer outside the SOC line rather than to the pager.
  • The query audit shows an analyst searched a colleague's mailbox with no case reference. What does that record establish?
    That the analyst's account submitted that query, against that index, over that time range, at that time, with no case linked. It does not establish that a human was at the keyboard, that the results were read or exported, or that there was no legitimate reason. It is enough to open a question, and it is the factual claim you can defend; anything stronger needs corroboration such as endpoint activity, exports or an interview.
  • Where should the query-audit log live, and who reads it?
    In a store that SOC analysts and SOC platform admins cannot alter or delete — append-only, ideally shipped outside the team's administrative control — because otherwise the subject of a future case administers their own evidence. Review belongs to a function outside the SOC's reporting line, typically internal audit, privacy or compliance, on a defined cadence rather than only when someone complains.

A hospital logs which staff opened which patient record, not because clinicians are suspected, but because opening a record is an act with a subject who deserves an answer about who read it.

saying these in an interview costs you the question

  • Assumes analysts are trusted so no audit is needed
  • Treats a query record as proof the analyst read the data
  • Stores the query audit in an index analysts administer
  • Omits the case reference, so no search has a stated purpose
  • Ignores export and direct-database read paths that bypass the audit

context

open as a page

With 90-day SIEM retention, a partner reports an intrusion seven months old — what can you no longer answer?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Anything about months four to seven. When access began, how it was obtained, and what it touched back then are unsearchable. You can describe only the last 90 days, and an empty result outside the window proves nothing.

open as a page

What is the difference between a log record's event time and its ingest time in a SIEM?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Event time is when the source says the activity happened; ingest time is when your collector received the record. Event time answers when it happened, ingest time answers the earliest moment the SOC could have known about it.

open as a page

What does two-person approval add before opening a named employee's mailbox telemetry?

level: middleimportance: should knowfreq 47%

basics

~20 s

It splits wanting the data from authorising it: the analyst who requests access cannot grant it. The recorded approval also bounds the access — named subject, named sources, a date range, an expiry — turning an open capability into a specific grant.

open as a page

How do you set a log-retention horizon from a right-skewed distribution of observed intrusion dwell times?

level: middleimportance: should knowfreq 45%

basics

~10 s

Take a high percentile of dwell, never the median, then add the lag from discovery to first search plus the weeks the case runs. Treat your own dwell data as truncated at current retention.

open as a page

A VPN appliance's syslog places a session seven minutes before the sign-in that authorised it - why?

level: middleimportance: should knowfreq 52%

basics

~20 s

Almost certainly the appliance's clock, not the order of events. BSD-style syslog carries no timezone and no year, so a drifting or locally set clock is copied straight into the SIEM and can place an effect before its cause.

open as a page

A works-council agreement bars per-employee endpoint telemetry outside an approved case. How do you run a hunt that needs it?

level: seniorimportance: should knowfreq 36%

basics

~20 s

Reshape the hunt to data you may hold: host-level or pseudonymised identifiers, a narrow field set, a short window, with names revealed only if a hit justifies approval. If it cannot be reduced, use the agreed break-glass or record an accepted blind spot.

open as a page

Your cold log archive rehydrates in nine hours and a live intrusion case needs eight-month-old sign-in logs — what do you do?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Start the narrowest possible restore immediately and keep working in parallel — nine hours only costs you the case if it is serialised. Then decide whether any containment action today actually depends on the restored data.

open as a page

A laptop reconnects and flushes six hours of buffered EDR events - what does that do to your hunt?

level: seniorimportance: should knowfreq 40%

basics

~20 s

It invalidates the negative result. The sweep covered the hours those records describe, but the records had not arrived yet, so nothing found meant nothing had arrived. Re-run the sweep over what has been received since.

open as a page

Three log sources disagree by minutes about one intrusion - how do you produce an ordering you can defend?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

Measure each source's offset using events that two sources both recorded, convert everything to UTC while keeping the raw fields, order by causality where the offsets overlap, and state the residual uncertainty instead of a false-precise second.

open as a page

The subject of an insider case sits inside the SOC's own reporting line. Who approves telemetry access, and how?

level: principalimportance: nice to knowfreq 24%

basics

~20 s

Approval must leave the security line entirely — a standing alternate such as internal audit, privacy or the general counsel's office. The subject also administers the tooling, so evidence, retention and the audit trail must move beyond their control before collection starts.

open as a page

A budget holder will fund six more months of security log retention only if you drop something else — how do you make the case?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Stop selling insurance and sell answerability: name the case questions the extra months make answerable and nothing else can. Offer an asymmetric horizon as the trade, and write down in advance what the shortened branch costs.

open as a page