Skip to content

CISSP Certification Guide / Chapter 28

Domain 7 Practice Test: Security Operations

Twenty-five original questions spanning the three crafts of security operations: watching (the SOC, the monitoring pipeline, logging content and integrity, clocks, retention, detection failure modes, the SIEM, and the regulations that anchor the floor), responding (the event-versus-incident line, evidence law from the Federal Rules of Evidence, chain of custody, the NIST SP 800-86 forensic phases, the RFC 3227 order of volatility, write blockers, GDPR breach notification, and the ISO/IEC 27001:2022 Annex A 5.24 through 5.28 incident controls), and keeping the promise (availability arithmetic, RAID, backup restore math, immutable and air-gapped backups, data center tiers, physical access operations, and MA-4 remote maintenance), with an answer key, rationales, and score-based triage rules.

How to take this test

Domain 7 is three crafts wearing one label. Chapter 25 built the floor: the SOC, the monitoring pipeline, the logging record, detection, the SIEM, and the regulations that force the discipline. Chapter 26 built the response: the incident lifecycle, evidence that survives scrutiny, and forensics. Chapter 27 built the machinery: the availability arithmetic, redundancy, backups, and the physical operations that keep the promise. The 25 questions below are drawn from all three, and they are written to test the seams between the crafts as much as the facts inside them.

Two skills carry this domain, and both are on display here. The first is attribution: given a scenario, you must name the function that owns it. Detect or respond or recover, log or monitor or retain, alert or investigate, the exam tests the boundaries between these pairs with the same lawyer-like care it applies to every other domain, and the wrong option in a question is almost always the correct name for a neighboring activity. The second skill is standard mapping: the exam names AU-3 and MA-4 and Article 33 and Requirement 10, and it expects you to know which control owns which requirement. When you read a stem, run both checks before you look at the options. Whose job is this, and what does the requirement say on paper?

A handful of questions carry math, and they are deliberate. Availability is a fraction with a named formula, RAID levels have survivability claims, and backup schemes have restore arithmetic. The exam rewards working those numbers cold, because every resilience conversation in a security career eventually becomes an argument about a number: how many nines, which RAID level, which restore set. The versioned facts here are drawn from the standards the chapters cite, and the rationales name them: NIST SP 800-61 Rev. 2, NIST SP 800-86, NIST SP 800-53 Rev. 5, RFC 3227, RFC 5905, ISO/IEC 27001:2022, PCI DSS v4.0, GDPR, and the Federal Rules of Evidence.

Set the clock for thirty minutes before you read the first stem: a minute and a quarter per item, the same pace this book assumes for the full 150-item session. Answer every question, even the ones you would rather skip, because a blank is wrong and the real engine never asks why you left it empty. Do not open the answer key early, and do not return to a question once you have moved past it. The adaptive exam gives you no item review, and the practice that transfers is the practice that reproduces that constraint. When a question forces a guess, guess cleanly and keep moving. The score sheet is where the analysis happens, not the test session.

When the clock stops, score yourself honestly and read the score interpretation before you touch anything else. The number is a triage instrument, not a verdict. It tells you which part of Domain 7 deserves your next study hours, and the specific questions you missed tell you which exact ideas to rebuild.

The 25 questions

  1. A security operations center’s alert queue is full at the start of the day shift. An analyst works through the queue, matching each alert against known signatures and documented playbooks, closing the ones that are clearly false, and passing the rest up the line. Which role is this analyst performing?

    A. Tier 1 triage B. Tier 2 investigation C. Tier 3 threat hunting D. Incident commander

  2. An automated scan from an unfamiliar internet address probes a company’s web servers for several hours. No vulnerability is exploited, no data is touched, and no system is damaged. Per the definitions in NIST SP 800-61 Rev. 2, how should the organization classify this activity?

    A. An incident, because the scanner came from outside the perimeter B. An incident, because any contact from an unknown source is a violation of acceptable use policy C. An event, because it is an observable occurrence with no policy violation and no threat to confidentiality, integrity, or availability D. An event, because it caused no damage, which is the definitional test

  3. A monitoring pipeline ingests logs from firewalls, endpoints, and identity servers. The firewall logs call the source address src_ip, the endpoint agent calls it source-address, and the identity server encodes it as a number. A correlation rule that expects a single field name matches almost nothing. Which stage of the monitoring pipeline is failing?

    A. Collection B. Normalization C. Storage D. Alerting

  4. An organization wants a metric that measures the average time between when an attacker’s action occurs and when the operations floor learns of it. Which metric is this?

    A. MTTR B. MTTD C. RPO D. ARO

  5. A security engineer is defining what each audit record must contain so that a later investigation can answer who did what, when, from where, and with what result. Which NIST SP 800-53 Rev. 5 control defines the required content of audit records?

    A. AU-2 B. AU-3 C. AU-9 D. AU-11

  6. An adversary compromises an administrator account that has rights to the logging server, and the logs from the compromised systems suddenly go silent after showing the adversary’s activity. Which design change most directly addresses this failure?

    A. Increase log verbosity on the compromised systems B. Store logs in a separate, append-only, write-protected store that the logged systems and their administrators cannot modify C. Double the retention period for all log sources D. Run the SIEM correlation rules more frequently

  7. During an investigation, the analyst cannot reconstruct the order of events because the endpoint, the firewall, and the identity server timestamps disagree by up to forty minutes. Which requirement addresses this directly?

    A. AU-8, which requires timestamps synchronized with an authoritative time source such as NTP B. AU-5, which requires alerting when logging fails C. SI-7, which requires integrity verification of software and firmware D. AU-11, which sets retention per organizational policy

  8. A merchant in scope for PCI DSS wants to confirm that its audit log retention satisfies Requirement 10. Which retention profile meets the requirement?

    A. Six months of history, with the most recent month immediately available for analysis B. At least 12 months of audit log history, with at least the most recent 3 months immediately available for analysis C. 24 months of history in cold storage, none of it hot D. Indefinite retention of all logs regardless of content

  9. A detection team tunes its rules so aggressively to reduce alert fatigue that a lateral movement attack runs for three days without a single alert firing. Which failure mode does this describe?

    A. A false positive B. A false negative C. A correctly suppressed alert D. A correlation gap

  10. An organization collects logs from 300 systems into one platform. The rules treat each event in isolation, so a sequence of failed logins followed by a successful login, a privilege change, and data access at 3 a.m. generates no alert even though every event is logged. What capability is missing?

    A. Aggregation B. Correlation C. Normalization D. Retention

  11. A responder must collect evidence from a running system that is believed to be compromised. Per the order of volatility in RFC 3227, which of the following should be collected before the others?

    A. A full disk image B. The contents of RAM and the process table C. Remote logging and monitoring data D. Temporary file systems

  12. In court, a party wants to prove what a database audit log contained and offers a readable printout of the log. The opposing party objects that the best evidence rule requires the original electronic file. Under the Federal Rules of Evidence, which statement is correct?

    A. The printout is inadmissible because only the electronic file is the original B. The printout is an original under Rule 1001 if it accurately reflects the stored data C. The printout is hearsay and requires the business records exception D. The electronic file must be produced on its original hardware

  13. A court is deciding how hearsay rules apply to two records: an authentication log generated automatically by a system, and a message typed by an employee. Which statement is correct?

    A. Both are hearsay, and both need the business records exception B. The authentication log is computer-generated and generally not hearsay, while the employee’s message is computer-stored and may be hearsay when offered for its truth C. Neither is hearsay because both are computer records D. The message is automatically admissible, while the log requires an expert witness

  14. A forensic team collects a hard drive, images it, and documents every transfer of custody in a signed log, including who had it, when, and what was done with it. What is the primary purpose of this documentation?

    A. To support the authenticity of the evidence by showing it was not altered, substituted, or contaminated B. To satisfy the order of volatility C. To determine the admissibility of expert testimony D. To calculate the hash of the image

  15. A forensic examiner has collected several drives and must now extract and reduce the data to what is relevant to the investigation, separating it from everything else. Per the NIST SP 800-86 forensic process, which phase is this?

    A. Collection B. Examination C. Analysis D. Reporting

  16. During disk acquisition, the examiner attaches the suspect drive to a forensic workstation through a hardware write blocker. What does the write blocker ensure?

    A. The image is created faster B. The source drive cannot be modified by the acquisition process C. The drive is automatically decrypted D. The image’s hash is published with the report

  17. A controller in the EU discovers a personal data breach affecting customer records. Under GDPR Article 33, what is the controller’s notification obligation to the supervisory authority?

    A. None, because only data subjects must be notified B. Notify without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to individuals C. Notify within 30 days regardless of the risk D. Notify only if the breach was caused by an external attacker

  18. An organization is implementing the ISO/IEC 27001:2022 Annex A incident controls and needs the control that requires procedures for identifying, collecting, acquiring, and preserving evidence. Which control is it?

    A. A 5.24 B. A 5.25 C. A 5.26 D. A 5.28

  19. A repairable component has a mean time between failures of 2,160 hours and a mean time to repair of 1 hour. Using the standard availability formula, what is its approximate availability?

    A. 95.0% B. 99.0% C. 99.95% D. 99.999%

  20. An administrator must choose a RAID configuration for a four-disk array that can survive the failure of any two disks at the same time. Which configuration meets that requirement?

    A. RAID 0 B. RAID 5 C. RAID 6 D. A single RAID 1 mirrored pair

  21. A backup scheme runs a full backup every Sunday night and a differential backup every weeknight. On Thursday morning the storage fails and the team must restore Wednesday’s state. Which set of backups does the restore require?

    A. The Sunday full and Wednesday’s differential B. The Sunday full and every differential since Sunday C. The Sunday full and every incremental since Monday D. Wednesday’s differential alone

  22. A ransomware campaign encrypts a production database, the synchronous replica at a second site, and every nightly snapshot on the shared storage array. What should have been in place to allow recovery?

    A. A second synchronous replica at a third site B. Immutable or air-gapped backups that the adversary cannot modify or delete C. RAID 10 on the production array D. More frequent snapshots

  23. A company must replace a failed cooling unit in its data center. The operating contract requires that no planned maintenance ever disrupts the IT load, and the facility design must support that. Which Uptime Institute tier is the minimum that guarantees this?

    A. Tier I B. Tier II C. Tier III D. Tier IV

  24. A terminated employee’s badge still opens the server room door two weeks after departure. Which operational control most directly closes this gap?

    A. Escorting all visitors at all times B. An automated revocation feed from human resources, paired with regular review of physical access logs per PE-6 C. Installing more cameras in the data center D. Requiring a second badge for all employees

  25. A vendor requests remote access to a production server for maintenance. Under NIST SP 800-53 Rev. 5 control MA-4, what must the organization do?

    A. Nothing, because vendor maintenance is exempt from access controls B. Document approval for the maintenance, monitor the session, and protect it with encryption and access controls C. Provide the vendor a standing privileged account so future maintenance is faster D. Require the vendor to work only on weekends

Answer key and rationales

  1. A. Tier 1 analysts sit on the front line: they triage alerts against known signatures and playbooks, close the obvious false positives, and escalate what they cannot resolve. Tier 2 investigates escalated alerts, Tier 3 hunts and designs detection, and the incident commander owns decisions during an active incident; none of them is the person working the queue at the front door.

  2. C. NIST SP 800-61 Rev. 2 defines an event as any observable occurrence in a system or network, and an incident as a violation or imminent threat of violation of security policies, procedures, or acceptable use policies, or a threat to confidentiality, integrity, or availability. Scanning with no exploitation is an observable occurrence with neither consequence, so it is an event. Origin alone does not make an event an incident, and the definitional test is policy violation or threat to CIA, not whether damage occurred.

  3. B. Normalization translates vendor dialects into a common schema so events from different sources can be compared, and the question describes exactly that failure: three sources name the same address three ways, and the rules cannot connect them. Collection got the data in, storage kept it, and alerting never got a coherent pattern to evaluate; the break is in the translation stage.

  4. B. MTTD, mean time to detect, is the average time between a malicious action and the organization learning of it. MTTR is the time from detection to containment or resolution, RPO is a recovery point objective from continuity planning, and ARO is the annualized rate of occurrence from risk math; none of them measures the gap between action and awareness.

  5. B. AU-3, Content of Audit Records, requires each record to establish what type of event occurred, when, where, from what source, with what outcome, and which identities were involved: type, time, location, source, outcome, identity. AU-2 governs which events are logged, AU-9 protects audit information from modification and deletion, and AU-11 governs retention; AU-3 is the content control.

  6. B. The logs stopped because the adversary reached the thing that wrote and stored them, and the defense is architectural: an append-only, write-only-to-authorized-processes, separately protected store that the logged systems and even their administrators cannot modify, the practical translation of AU-9 and the reason WORM storage exists. More verbosity, longer retention, and faster correlation rules all assume the adversary cannot already rewrite the record, which is exactly the assumption that just failed.

  7. A. AU-8, Time Stamps, requires synchronized clocks from an authoritative source, the standard implementation being NTP per RFC 5905, and ISO/IEC 27001:2022 Annex A 8.17 makes the same demand. The question is the classic consequence of missing synchronization: events that cannot be ordered are events that cannot be correlated or reconstructed. AU-5 handles logging failure alerts, SI-7 handles integrity verification, and AU-11 handles retention; none of them makes timestamps agree.

  8. B. PCI DSS v4.0 Requirement 10 requires at least 12 months of audit log history, with at least the most recent 3 months immediately available for analysis. Six months is short, 24 months in cold storage fails the hot-three-months clause, and indefinite retention ignores the legal and privacy forces that retention policy must balance, notably GDPR Article 5(1)(e) and the reality that logs contain personal data.

  9. B. A false negative is the miss: no alert fires while an attack is actually underway, and it is the more dangerous failure because it creates the illusion of monitoring. A false positive is the opposite error, an alert with nothing behind it. The rule was not correctly suppressing a benign event, and nothing about this scenario is a correlation gap, because the attack produced no alert at all.

  10. B. Correlation connects events across sources and time to reveal patterns no single event shows, and the failed-login-to-privilege-change-to-data-access chain is the textbook correlated story. Aggregation, pulling events into one place, is exactly what this organization already does, and normalization and retention are not the missing piece; the platform collects everything and connects nothing.

  11. B. RFC 3227 orders collection from most to least volatile, and RAM and the process table sit far above disk in that order: registers and cache first, then routing tables, the ARP cache, the process table, kernel statistics, and memory, then temporary file systems, then disk, then remote logging. A responder who powers the system down to image the disk destroys the memory evidence that matters most. The disk image, remote logs, and temp files all come after the live memory capture.

  12. B. The best evidence rule, Federal Rules of Evidence Rule 1002, requires an original to prove the content of a writing, recording, or photograph, and Rule 1001 defines the original for computer data: any printout or other output readable by sight that accurately reflects the data. A faithful printout of the log is the original for purposes of the rule. The electronic file is not the only original, hearsay analysis is a separate question, and producing original hardware is not required.

  13. B. The boundary the rule draws is between machine and person. An authentication log is computer-generated, the product of system processing with no human declarant, so hearsay analysis generally does not apply. A message typed by an employee is computer-stored: a human wrote it, and if it is offered for its truth, the hearsay rules apply, with the business records exception of Rule 803(6) as the classic path in. Neither record is exempt from all analysis, and the two are not treated alike.

  14. A. Chain of custody is the unbroken, signed record of possession, location, and handling that demonstrates the evidence was not altered, substituted, or contaminated, which is the mechanism that makes the authenticity factor from NIST SP 800-86 real. The order of volatility is a collection-time question, expert testimony admissibility is governed by Rule 702 and Daubert factors, and the hash is an integrity check that complements custody documentation rather than replacing it.

  15. B. NIST SP 800-86 lays out four phases in order: collection, then examination, which extracts and reduces the collected data to what is relevant, then analysis, which interprets the examined artifacts and draws conclusions, then reporting. Separating relevant data from everything else is the examination phase. Collection already happened, and drawing conclusions and writing the record belong to the later phases.

  16. B. A hardware write blocker sits between the suspect drive and the workstation and permits only read access, so the act of acquiring the evidence cannot modify the source. It does not speed imaging, decrypt anything, or publish hashes; speed, decryption, and integrity reporting are separate concerns, and the blocker exists for one reason, keeping the source pristine so the image is defensible.

  17. B. GDPR Article 33 requires the controller to notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals. Article 34 separately requires communication to data subjects when the breach is likely to result in a high risk to their rights and freedoms. There is a notification duty, it has a 72-hour shape, and it does not depend on who caused the breach.

  18. D. Annex A 5.28, Collection of Evidence, requires procedures for identifying, collecting, acquiring, and preserving evidence in accordance with applicable legal and regulatory requirements. The family around it is the lifecycle: A 5.24 plans and prepares, A 5.25 assesses and decides on events, A 5.26 responds, A 5.27 learns, and A 5.28 preserves. Evidence collection is the 5.28 job.

  19. C. The availability formula is A = MTBF / (MTBF + MTTR), so 2,160 / (2,160 + 1) = 2,160 / 2,161, approximately 99.95%. The formula is why redundancy works: shrinking effective repair exposure while growing the interval between effective failures pushes the fraction toward one without requiring any single component to be perfect. The other options are not what the arithmetic produces.

  20. C. RAID 6 writes two parity sets across the array and survives the failure of any two disks, which is the property the question demands. RAID 0 has no redundancy and survives nothing, RAID 5 survives one disk, and a single RAID 1 pair survives one of its two drives; none of them tolerates any two simultaneous failures.

  21. A. A differential backup accumulates everything changed since the last full backup, so restoring Wednesday’s state requires the Sunday full plus the single most recent differential, Wednesday’s, which already contains the changes from Monday, Tuesday, and Wednesday. The scheme has no incrementals, so option C describes a different scheme entirely, and a differential alone cannot reconstruct the base state.

  22. B. Replication, snapshots, and mirrors all copy whatever exists, including the encryption that just happened, and the synchronous replica and the snapshots in this scenario share the production array’s fate. Recovery from an adversary who actively destroys copies requires backups that are immutable, write-once enforced by object locks or WORM media, or air-gapped, isolated from the networks a compromise can reach, the discipline behind NIST SP 800-53 Rev. 5 CP-9. Another replica, RAID, and more snapshots each add another copy of the same doomed data.

  23. C. Tier III, concurrently maintainable, is the tier whose defining property is that planned maintenance, testing, and replacement can be performed without disrupting the IT load, through N+1 capacity and multiple independent distribution paths. Tier I has a single path and no redundancy, and Tier II adds redundant components but keeps a single path, so maintenance still takes the load down. Tier IV also meets the requirement, but the minimum that guarantees it is Tier III.

  24. B. The revocation gap, a credential that outlives its authorization, is closed by process and evidence: an automated feed from human resources that deactivates the badge on departure, and the regular review of physical access logs that PE-6 requires, which would surface a terminated employee’s badge reads. Escorts, cameras, and dual badges address other risks; none of them retires the specific credential that should no longer exist.

  25. B. MA-4, Nonlocal Maintenance, requires documented approval for each remote maintenance instance, monitoring of the session, and protection of the session through encryption and access controls, because a vendor’s remote connection is a privileged doorway into the environment. Vendor maintenance is not exempt, a standing privileged account is exactly the standing door the control refuses, and a schedule does not substitute for authorization, monitoring, and protection.

Reading your Domain 7 score

Score yourself against the bands this book set in Chapter 1 for every domain test:

Score Verdict Action
0–14 (below 60%) The domain’s concepts have not landed. Re-read Chapters 25, 26, and 27, redo all of their practice questions, and retake this test in three to five days.
15–19 (60–80%) The concepts are mostly there. Review only the rationales you missed, redo those questions until you can explain each rationale aloud, and keep Domain 7 in weekly spaced review.
20–25 (above 80%) The domain is in good shape. One weekly review pass. Spend the reclaimed hours on weaker domains.

The single number hides the information you need, so break the misses down by area. Domain 7 is three crafts under one label, watching, responding, and keeping the promise, and the triage that matters is at the topic level:

Area Questions If you missed 2 or more
The floor and its vocabulary: SOC tiers, events and incidents 1, 2 Re-read Chapter 25’s SOC section: the tier roles, and the event-versus-incident line from NIST SP 800-61 Rev. 2.
The pipeline and its metrics 3, 4 Re-read Chapter 25’s monitoring pipeline section: collection, normalization, storage, alerting, and what MTTD and MTTR actually measure.
Log content, integrity, and clocks 5, 6, 7 Re-read Chapter 25’s logging section: the AU-3 content elements, AU-9 and WORM, and AU-8 time synchronization.
Retention and regulation 8 Re-read Chapter 25’s retention section: PCI DSS v4.0 Requirement 10, GDPR Article 5(1)(e) storage limitation, and the legal hold override.
Detection failure modes and the SIEM 9, 10 Re-read Chapter 25’s baselining and SIEM sections: false positives versus false negatives, and aggregation versus correlation.
Evidence law 12, 13, 14 Re-read Chapter 26’s evidence section: Rules 1001 and 1002, hearsay and Rule 803(6), and chain of custody.
Forensics order and tools 11, 15, 16 Re-read Chapter 26’s forensics section: the RFC 3227 order of volatility, the four NIST SP 800-86 phases, and write blockers.
Notification and incident standards 17, 18 Re-read Chapter 26’s controls section: GDPR Articles 33 and 34, and the ISO/IEC 27001:2022 Annex A 5.24 through 5.28 family.
Availability arithmetic and RAID 19, 20 Re-read Chapter 27’s arithmetic and storage sections: the availability formula, the nines table, and the RAID level table.
Backups and ransomware recovery 21, 22 Re-read Chapter 27’s backups section: full, incremental, and differential restore math, and immutable and air-gapped backups.
The room and physical operations 23, 24, 25 Re-read Chapter 27’s physical operations section: data center tiers, PE-6 and PE-8, and MA-4 remote maintenance.

Two habits make the score useful. First, log the result and the area misses on your score sheet, because the full practice exam in Chapter 33 will re-test this domain and you want the comparison. Second, treat a miss pattern as a question about process, not just facts. If your misses cluster on the attribution questions, 1 through 10 and 23 through 25, your problem is mapping a scenario to its owning function, and the fix is to name the function before you look at the options: is this detection, response, recovery, or the room? If your misses cluster on the standards and evidence questions, 12 through 18, your problem is control mapping, and the fix is to redraw the control table from Chapters 25 and 26 cold: control name, requirement, and the scenario it answers.

What the score means for your plan

Domain 7 carries 13 percent of the current outline’s weight, and it is the domain where the exam’s favorite plot, the adversary inside the network, actually runs. The watching questions reward the manager who knows what each layer of the floor is for and what a detection system can and cannot see. The responding questions reward the investigator who can keep a story alive from the first alert to the courtroom. The machinery questions reward the operator who knows which failure each control survives, and who is never surprised to learn that RAID does not stop ransomware.

Domain 7 also completes the operational spine of the exam. Monitoring hands the timeline to incident response, incident response hands the recovered service to resilience engineering, and all three depend on the physical room underneath. If your score shows the crafts in balance, you are ready for the last two domains and the exam itself. If it shows one craft missing, that craft is where your hours go, because the full practice exam in Chapter 33 will test the same material from a different angle, and the weak craft will be waiting there.

One thing worth noticing as you close Part VIII: you have now finished the last pure operations domain. Part IX moves to the other side of the build, software development security, where the questions shift from defending what runs to building what does not break in the first place. The record-keeping discipline of this part, the incident mindset, and the availability arithmetic all carry over. Pass this test at the level your score band demands, log the misses, and move to Domain 8 with the floor, the response, and the machinery all in working order.