The third domain (22%) โ covers SIEM/SOAR configuration, vulnerability management, incident response phases, digital forensics, and threat hunting with MITRE ATT&CK.
At 22%, Security Operations tests your ability to detect, investigate, and respond to threats. This includes building detection rules in SIEM, prioritizing vulnerability remediation, executing incident response procedures, and proactively hunting threats using adversary behavior frameworks.
Build detection rules, tune baselines, automate response playbooks.
Prioritize with CVSS/EPSS, integrate SCA and SBoM.
Execute PICERL phases, collect forensic evidence, hunt with MITRE ATT&CK.
Click each card to expand. Four areas cover the full Domain 3 objective set.
12 terms covering Domain 3's operations, forensics, and threat intelligence concepts. Click to flip.
Question 1 of 8 ยท Score: 0