// ExamRange

CSA (312-39) SOC Simulation Lab

Welcome to the SOC. In this interactive simulation, you will step into the early, chaotic stages of a major security incident. You will learn the critical incident response roles defined by NIST and how to manage communication during a multi-departmental healthcare data breach.

Scenario Context

A high-severity alert triggered at Centex Healthcare indicating anomalous database exports from the Electronic Health Records (EHR) system. Sarah Chen, an L1 SOC Analyst, is currently attempting to trace the IP address and block the exfiltration via the Palo Alto firewall.

However, a major incident bridge has been opened. Because it involves Patient Health Information (PHI), Legal, HR, and the external Managed Security Service Provider (MSSP) have all joined the bridge. Everyone is demanding updates directly from Sarah, bringing technical containment to a grinding halt.

Security Environment

Review the active ServiceNow Incident Ticket work notes showing the communication breakdown during the response.

### SERVICENOW TICKET: INC-20260408-992 ACTIVE Status: Active | Severity: CRITICAL (P1) Impacted System: Centex_EHR_Prod [14:22] Sarah Chen (L1_Analyst): Blocked malicious IP on perimeter. Investigating 15 compromised accounts in Entra ID. [14:25] HR_Director: Do we need to send the nursing staff home? Are their accounts locked? What's the status? [14:26] Legal_Counsel: Is PHI confirmed compromised? We have 72 hours for HHS/OCR notification. Need an immediate update on data volume! [14:28] MSSP_Lead: We are awaiting approval to completely isolate the DB server. Who is running this bridge? [14:30] Sarah Chen (L1_Analyst): Please hold, everyone. I can't read the Azure logs and answer all these questions at the same time...

Question

Sarah Chen is a Level 1 security analyst in the Security Operations Center (SOC) team of Centex Healthcare, a regional hospital network. The SOC team has detected a potential data breach involving unauthorized access to patient records. Multiple departments need constant updates: Legal needs to assess HIPAA compliance implications, HR needs to coordinate staff training responses, and their managed security service provider requires technical details to assist with containment. Which role effectively serve as the central point of communication between all these stakeholders?
SOC Hint: You need the person who takes command of the incident response process, acts as a liaison to management, and abstracts the "noise" away from the technical analysts so they can actually do their jobs.
Senior SOC Analyst Debrief

Situation Report

The SOC is currently experiencing a "communication DDoS." The L1 analyst (Sarah) is simultaneously trying to perform technical containment (blocking IPs, investigating Azure logs) while acting as the primary communicator for Legal, HR, and external partners. This violates core Incident Response principles. Technical responders must be allowed to focus on the technical threat, completely shielded from executive and administrative noise.

Why Option C is Correct

Incident Manager. In the EC-Council CSA and NIST frameworks, the Incident Manager is the central authority during an active incident. Their primary role is to coordinate the response effort, serve as the central point of communication, liaise with internal stakeholders (Legal, HR, C-Suite) and external entities (MSSPs, Law Enforcement), and make critical business decisions (like approving the DB isolation). They abstract the communication burden away from the technical analysts.

Why the Others Fail

B (Incident Coordinator/Handler): While titles can vary by organization, in strict framework terms, coordinators/handlers are the technical experts (like Sarah) who are "hands-on-keyboard" executing the containment, eradication, and recovery steps.

A (Public Relations Manager): The PR Manager handles external communication to the media, public, and patients. They rely on the Incident Manager to give them the facts; they do not coordinate the internal technical/legal response.

D (Information Security Officer): The ISO or CISO oversees the entire security program and risk posture. While they will be informed of the breach, they do not typically run the minute-by-minute operational communication bridge of a specific incident.

Mini Lesson: The Incident Command System

Effective SOCs borrow their response structure from physical emergency services (like firefighting). When a P1 incident triggers, the following hierarchy must be established immediately:

  • Incident Manager (The Commander): Runs the bridge. Says "Legal, I will get you a data volume estimate in 30 minutes. MSSP, you are clear to isolate the DB."
  • Scribe: Documents every action, timestamp, and decision in the ticketing system (e.g., ServiceNow) to ensure a solid chain of custody and post-incident report.
  • Incident Handlers / Analysts: Stay muted on the bridge unless spoken to by the Manager. They analyze logs, write YARA rules, and execute containment scripts.

Ready to level up your SOC skills?

Practice more real-world threat hunting and incident response scenarios based on the EC-Council CSA framework.

Explore More CSA Simulations