QUESTIONS AND ANSWERS
Erik's SOC team is divided into groups with different functions. Which three teams are responsible for
the development, implementation, and maintenance of security policies?
Endpoint Security, Network Security, and Cloud Security.
Enterprise Security, Endpoint Security, and Cloud Security.
HelpDesk Security, Operational Security, and Information Technology Security.
Telemetry Security, Forensics Security, and Threat Intelligence Security
Endpoint Security, Network Security, and Cloud Security.
What management method did the SOC team utilize to collect information on security incidents and
their statuses?
Case management
Knowledge management
Asset management
Threat management
What tool or technology can Erik and the SOC team use to detect and prevent accidental or malicious
release of proprietary or sensitive information?
Vulnerability management
URL Filtering
SSL Decryption
Data Loss Prevention (DLP)
Data Loss Prevention (DLP)
What tool or technology can Erik and the SOC team use to provide visibility into HTTPS traffic to find
IOCs or high-fidelity indicators?
Application Monitoring
SSL Decryption
URL Filtering
Data Loss Prevention
SSL Decryption
Erik is concerned that some of these alerts may be critical and the team will need help mitigating all of
them. What should Erik do?
Deploy more SIEMs to collect and process the data before having a SOC analyst interpret the data and
take appropriate action.
Deploy additional endpoint security to protect servers, PCs, laptops, and tablets so that alerts that are