Step into the shoes of a Tier 3 SOC Analyst. In this simulation, you will analyze SOC project management data to map organizational activities directly to the formal Incident Response (IR) lifecycle framework.
GlobalTech Dynamics recently suffered a supply chain breach that exposed their previous MSSP's slow response times. In response, the board approved a major budget to build an internal, state-of-the-art SOC. James Rodriguez, the new Lead SOC Manager, is currently focused on establishing the foundational capabilities before the SOC officially "goes live."
To ensure the new SOC operates effectively under pressure, James is tracking several major initiatives across the team's project management platform, aligning them with formal Incident Response methodologies.
You review the current Jira Epic tracking the SOC standup progress to understand the team's current operational state:
James Rodriguez has recently taken over as the lead SOC manager at GlobalTech Dynamics, a Fortune 500 company with a growing cyber threat landscape. She is tasked with strengthening the SOC's capabilities to protect the organization's critical assets. Her team is currently deploying a $2M state-of-the-art SOC facility, creating detailed incident response playbooks, running tabletop exercises to simulate real-world attacks, and training a 15-member incident response team to handle alerts and incidents efficiently. In the context of the Incident Response Process Flow, which phase best aligns with these activities?
The SOC is currently in a foundational building phase. There is no active breach being fought in this scenario. Instead, James is acquiring tools, establishing physical infrastructure, writing standard operating procedures (SOPs/Playbooks), and upskilling the analysts. In the real world, a SOC cannot successfully contain a threat if they haven't first defined how to contain it and secured the tools required to do so.
According to the standard Incident Response Lifecycle (like NIST SP 800-61), the Preparation phase encompasses all activities performed before an incident occurs to ensure the organization can effectively respond. This includes establishing the IR team, acquiring necessary hardware/software (the $2M facility), developing playbooks, and conducting tabletop training exercises. It is the most critical phase—if you fail to prepare, you prepare to fail.
As a SOC Analyst, you must implicitly know where you are in the IR lifecycle during any shift. The NIST framework defines four distinct phases:
Want to improve your SOC detection logic and IR skills?
Explore more CSA 312-39 simulations on ExamRange ➔