CSA (312-39) SOC Simulation Lab

In this simulation, you will analyze a sophisticated threat actor bypassing traditional technical controls. You will learn to identify different threat intelligence disciplines and how to pivot investigations when EDR and SIEM logs go dark.

Scenario Context

You are a Tier 3 SOC Analyst at Horizon Finance. Over the past three weeks, two executive email accounts were compromised, and sensitive board-level documents were exfiltrated.

Your L1 and L2 analysts are stumped. There are no malicious attachments, no zero-day exploit artifacts in the EDR console, and no anomalous PowerShell execution. The attackers seem to know exactly how to bypass Horizon's multi-layered defense architecture. You take over the incident response and begin correlating Microsoft 365 audit logs with physical security logs and external communications.

Security Environment

Reviewing the limited telemetry available, you notice a complete absence of traditional technical indicators, but a strong pattern of anomalous human interaction.

[EDR_STATUS] :: Agent Health: Normal | Unresolved Alerts: 0 | Exploit Guard: Active [SIEM_CORRELATION] :: Rule "Anomalous Login Location" -> Triggered: False [SIEM_CORRELATION] :: Rule "Suspicious Inbox Rule Creation" -> Triggered: False [O365_AUDIT_LOG] :: User: CEO_Horizon Event: MailItemsAccessed Context: Interacting with external sender "d.miller@fin-journal-international.com" Subject: "Interview Request: Horizon Finance Q3 Strategy" [O365_AUDIT_LOG] :: User: VP_Risk Event: Meeting Accepted Context: External sender "consulting@risk-assess-global.net" Subject: "Free Preliminary Cloud Risk Assessment - Intro Call" [THREAT_INTEL_BRIEF] :: STIX_REPORT_ID: TI-2023-881 Summary: Threat group UNK-FIN-9 focuses on high-value targets via psychological manipulation. Group rarely deploys custom malware until deep trust is established. Primary initial access vector: Direct human engagement, fake personas, and rapport building.

Question

During a routine threat intelligence briefing, a SOC analyst comes across a classified report detailing a sophisticated cybercrime syndicate targeting executives of high-profile financial institutions. Unlike traditional malware-based attacks, these adversaries rarely leave digital footprints and seem to anticipate security measures in advance. While analyzing recent incidents, the analyst discovers that several breaches began with seemingly innocent conversations-a foreign journalist requesting an interview with a CEO, and a security consultant offering free risk assessments. Further investigations reveal that attackers socially engineered employees, manipulated trust, and extracted critical security details long before launching technical attacks. Realizing that the most valuable intelligence may not come from log files or malware analysis, the analyst decides to focus on intelligence that involves deception detection, and psychological profiling to uncover the true intent and methods of the attackers. Which type of intelligence is the analyst leveraging in this situation?

SOC Hint: Look closely at the data sources the analyst is prioritizing: "deception detection," "psychological profiling," and "seemingly innocent conversations." This relies on interpersonal interaction, not scanning public records or analyzing packet captures.

Expert Insight: Tier 3 SOC Analysis

What is happening here?
The SOC is dealing with a highly sophisticated Social Engineering / Advanced Persistent Threat (APT) campaign. The attackers are completely bypassing the technical perimeter (Firewalls, EDR, SIEM detection rules) by targeting the "human perimeter." Because the executives are willingly engaging with these fake personas and handing over information, the technical tools log the activity as authorized, benign traffic.

Why Option C (Human Intelligence) is Correct:
Human Intelligence (HUMINT) involves gathering information through direct interpersonal contact. In cybersecurity, this includes analyzing social engineering tactics, interviewing victims, understanding psychological profiling, and sometimes directly interacting with threat actors (e.g., undercover on dark web forums). The analyst in the scenario is focusing on human behavior, deception, and trust manipulation—the core elements of HUMINT.

Why the other options are incorrect:

SOC Mini-Lesson: When Telemetry Fails

As a senior analyst, you will encounter incidents where the SIEM is entirely green, but a breach has still occurred. This is common in Business Email Compromise (BEC) and whaling attacks.

The Pivot: When technical telemetry fails to show exploitation, pivot to behavioral telemetry. Stop looking for powershell.exe -enc and start looking for:

  • Anomalous Mailbox Delegation (Did the CEO grant access to an assistant they don't have?)
  • Communication Pattern Changes (Is an executive suddenly emailing a new external vendor at 3 AM?)
  • Analyzing the context of communications (HUMINT) rather than just the metadata.

Security is not just packets and logs; it is understanding the adversary's intent and how they manipulate human psychology to bypass your tools.

Ready to validate your SOC analytical skills further?

Explore more CSA simulations at ExamRange >>