CSA (312-39) SOC Simulation Lab

Welcome to the SOC Operations lab. In this module, you will learn to map operational, tactical, and strategic tasks to their proper roles within a Security Operations Center hierarchy.

Scenario Context

InfoSystem LLC, a US-based financial services firm, has relied on a Managed Security Service Provider (MSSP) for the last three years. Due to regulatory changes and data sovereignty concerns, the board of directors has approved the budget to establish an in-house Security Operations Center (SOC).

Before any SIEM architecture is deployed or EDR agents are rolled out, foundational governance must be established to ensure the SOC aligns with business objectives.

Security Environment

You have intercepted an internal email outlining the SOC deployment project charter phase 1 deliverables:

# TO: IT Leadership Team
# SUBJECT: SOC Phase 1 - Governance & Strategy Kickoff

Project_Phase: 1.0 Governance
Lead_Owner: John [Role Undefined]
Deliverables:
  - Finalize enterprise security strategy (3-year roadmap).
  - Draft SOC standard operating procedures (SOPs).
  - Establish data retention and incident response policies.
  - Define budget allocation for SIEM licensing.
Status: Pending Board Approval

Question

InfoSystem LLC, a US-based company, is establishing an in-house SOC. John has been given the responsibility to finalize strategy, policies, and procedures for the SOC. Identify the job role of John.
SOC Hint: Look closely at the tasks. "Strategy, policies, and budget" are executive-level governance tasks, not operational alerts or engineering tasks. Which role sits at the top of the security org chart?
Senior SOC Analyst Insight

What is happening here?

When you transition from an MSSP to an internal SOC, the worst mistake an organization can make is buying a SIEM (like Splunk or Sentinel) and blindly turning on all data feeds without a plan. John is acting in an executive capacity. He is establishing the "rules of engagement"—what logs we care about legally, how long we store them (retention policy), and the overarching strategy of the SOC.

Why B (CISO) is the Correct Answer

The Chief Information Security Officer (CISO) is a C-level executive role. The CISO is responsible for aligning the security organization with business goals. Finalizing overarching strategy, creating enterprise-wide security policies, and managing the security budget squarely fall on the CISO's shoulders.

Why the others are incorrect

  • A & D (L1/L2 Analysts): These are operational roles. They monitor the SIEM console, triage alerts, and respond to incidents. They execute the playbooks; they do not write the overarching enterprise policy.
  • C (Security Engineer): This is a tactical role. An engineer builds and maintains the SIEM infrastructure, writes custom parsers, and ensures log sources (like Windows Event Logs or AWS CloudTrail) are flowing properly. They follow the strategy dictated by leadership.

MINI LESSON: The SOC Role Hierarchy

In a real-world SOC, understand the distinction between the three domains of operation:

  • Strategic (Executive Level): CISO, SOC Director. Focuses on budget, risk management, compliance, policies, and business alignment.
  • Tactical (Engineering/Architecture Level): Security Engineers, Threat Hunters, L3. Focuses on building detections, tuning the SIEM, maintaining infrastructure, and advanced threat intelligence (STIX/TAXII integrations).
  • Operational (Frontline Level): L1 and L2 Analysts. Focuses on day-to-day log analysis, alert triage, incident containment, and remediation.

Mastered this concept? Take your skills further.

Explore more CSA simulations at ExamRange