CSA (312-39) SOC Simulation Lab

Welcome to the Tier 3 SOC environment. In this module, you will analyze Incident Response frameworks. You will learn the critical differences between IR policies, processes, and procedures from a real-world SOC management perspective.

Scenario Context

You are an Incident Commander at a major healthcare provider. Your team is currently handling a potential LockBit ransomware outbreak. During the containment phase, the SOC Manager requests a status update on the Service Level Agreements (SLAs) and Mean Time to Respond (MTTR) metrics to ensure the team is complying with regulatory requirements.

Security Environment

Incident Ticketing System (TheHive / ServiceNow) Snippet:

TICKET_ID: INC-2023-9981 | SEVERITY: CRITICAL (Ransomware)

STATUS: Containment Phase

--------------------------------------------------

[METRICS TRACKING]

Time to Triage (TTT): 12m (SLA Limit: 15m) - PASS

Time to Contain (TTC): 45m (SLA Limit: 60m) - IN PROGRESS

--------------------------------------------------

[ACTION LOG]

14:00 - EDR Alert generated by CrowdStrike Falcon.

14:12 - L1 Analyst escalated to L2 Incident Responder.

14:15 - Initiated attached playbook: Ransomware_IR_Doc_v3.pdf

14:20 - SOC Manager Note: "Ensure we log all time management details for legal review per the referenced document."

Note: The team must follow a specific type of document that strictly dictates these performance measures and timeframes.

Question

Which of the following contains the performance measures, and proper project and time management details?

A Incident Response Policy
B Incident Response Tactics
C Incident Response Process
D Incident Response Procedures

Expert Insight: Senior SOC Analyst Mentorship

1. What is happening?

In the middle of a critical incident (like ransomware), chaos can easily take over. To prevent this, SOCs rely on heavily structured documentation. The ticketing system shown in the environment tracks MTTR and SLAs precisely because regulatory bodies (like HIPAA or GDPR) require proof of timely containment. The SOC must follow specific, step-by-step documentation to meet these legal and operational time requirements.

2. Why the Correct Answer is Correct

Correct Answer: D (Incident Response Procedures)
Procedures (often called Playbooks or SOPs in the SOC) provide the granular, step-by-step instructions. They dictate who does what, and exactly how long they have to do it. Performance measures (like "Contain a compromised host within 60 minutes") and time management details (like "Log update in Jira every 15 minutes") live exclusively in the procedure layer.

3. Why the Other Options are Wrong

  • A. Policy: The highest-level document. A policy simply states management's directive (e.g., "The organization will have an IR capability"). It contains no technical details or specific time limits.
  • B. Tactics: Tactics refer to the technical maneuvers used by analysts (e.g., sinkholing malicious domains, running EDR isolation scripts). They are technical actions, not project/time management documents.
  • C. Process: The process is the high-level workflow (e.g., NIST's Preparation → Detection → Containment → Eradication → Recovery). It tells you the phases, but not the specific granular metrics or 15-minute SLA timers.

MANDATORY MINI-LESSON: The Governance Hierarchy in SOC Operations

As a Tier 3 analyst, you will be expected to draft and review documentation. You must understand the strict hierarchy of governance frameworks:

  • POLICY (Why): Executive level. "We will protect customer data." (Mandatory)
  • STANDARD (What): Rule level. "We will use AES-256 encryption." (Mandatory)
  • PROCESS (Workflow): Phase level. "First we isolate, then we remediate." (Mandatory)
  • PROCEDURE (How/When): Analyst level. "Click this button in CrowdStrike. You have 15 minutes to complete this step. Record time in Jira." (Mandatory)
  • GUIDELINE: Advice level. "Try looking at these extra logs if you get stuck." (Optional)

Detection Logic Application: When auditing SOC performance, SIEM dashboards are built to track Analyst performance against the SLAs written specifically in the Procedures. If the Procedure says MTTR is 1 hour, your Splunk dashboard will flash red at 61 minutes.

Ready to level up your Incident Response management skills?

Explore more CSA simulations on ExamRange