Security Expert Correcting a Junior Analysts Triage Error Quiz

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 8865 | Total Attempts: 106,055
| Questions: 20 | Updated: Aug 13, 2026
Please wait...
Question 1 / 21
🏆 Rank #--
0 %
0/100
Score 0/100

1. A junior analyst assigns a 'false positive' label to an alert for a user accessing sensitive files outside normal business hours, because 'the user account is legitimate.' What correction is needed?

Submit
Please wait...
About This Quiz
Security Expert Correcting A Junior Analysts Triage Error Quiz - Quiz

This quiz evaluates your ability to identify and correct common triage errors in security incident analysis. You'll assess real-world scenarios where junior analysts misclassify threats, misjudge severity, or overlook critical indicators. Master the skills needed to review incident reports, validate alert accuracy, and apply CompTIA Security+ best practices to improve... see moreyour team's threat response. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A junior analyst marks a 'suspicious network connection to known malicious IP' as 'false positive' because 'the connection was blocked.' What is the error in this conclusion?

Submit

3. A junior analyst dismisses an alert for 'suspicious scheduled task creation' because 'scheduled tasks are a normal administrative function.' What correction is needed?

Submit

4. A junior analyst receives an alert for 'process injection detected' but closes it because 'the injection target process is low-risk.' What flaw exists in this reasoning?

Submit

5. A junior analyst marks a 'PowerShell script execution' alert as 'routine' because 'PowerShell is used by legitimate IT staff.' What correction should be made?

Submit

6. A junior analyst ignores multiple alerts for the same user account because 'they all arrived within a short time window and might be correlated.' What error exists?

Submit

7. A junior analyst categorizes a 'Mimikatz process execution' alert as 'medium priority' because 'the tool is known and documented.' What correction is required?

Submit

8. A junior analyst receives an alert for 'ARP spoofing detected' but closes it because 'the alert came from a test environment.' What is the flaw in this triage decision?

Submit

9. A junior analyst notes that a suspicious process 'wmiexec.exe' appeared briefly and closed, then marks it 'informational' because 'it's not running now.' What correction applies?

Submit

10. A junior analyst dismisses a registry modification alert for 'HKLM\System\Run' because 'it was initiated by an admin.' What error occurs in this assessment?

Submit

11. A junior analyst marks a phishing email with embedded malware as 'low priority' because the sender domain appears legitimate. What is the primary error in this triage decision?

Submit

12. A junior analyst reports a port scan from an external IP as 'low priority' because 'only ports above 10000 were scanned.' What is the logical flaw?

Submit

13. A junior analyst closes an alert for 'certificate validation failed' on a critical API endpoint, reasoning that 'SSL errors happen all the time.' What error exists here?

Submit

14. A junior analyst marks a Windows event log entry 'EventID 4625 (failed login)' appearing 50 times in 10 minutes as 'routine activity.' How should this be corrected?

Submit

15. A junior analyst ignores a spike in outbound traffic from a workstation to an unknown IP because 'the user is working late.' What correction applies?

Submit

16. A junior analyst categorizes data exfiltration of 50 MB as 'low severity' because the database contains 500 GB total. What is the flaw in this reasoning?

Submit

17. A junior analyst notes that a DNS query for 'malicious-c2-domain.ru' is 'blocked by firewall, so no incident.' What error exists in this conclusion?

Submit

18. A junior analyst reports that 200 failed SSH login attempts against a server is 'normal background noise.' How should you correct this assessment?

Submit

19. A junior analyst dismisses an alert for unsigned executable running from %TEMP% because the file size is small (12 KB). What is the error in reasoning?

Submit

20. A junior analyst classifies an internal user account with failed login attempts from 15 different countries in one hour as 'medium severity.' What correction should you make?

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (20)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A junior analyst assigns a 'false positive' label to an alert for a...
A junior analyst marks a 'suspicious network connection to known...
A junior analyst dismisses an alert for 'suspicious scheduled task...
A junior analyst receives an alert for 'process injection detected'...
A junior analyst marks a 'PowerShell script execution' alert as...
A junior analyst ignores multiple alerts for the same user account...
A junior analyst categorizes a 'Mimikatz process execution' alert as...
A junior analyst receives an alert for 'ARP spoofing detected' but...
A junior analyst notes that a suspicious process 'wmiexec.exe'...
A junior analyst dismisses a registry modification alert for...
A junior analyst marks a phishing email with embedded malware as 'low...
A junior analyst reports a port scan from an external IP as 'low...
A junior analyst closes an alert for 'certificate validation failed'...
A junior analyst marks a Windows event log entry 'EventID 4625 (failed...
A junior analyst ignores a spike in outbound traffic from a...
A junior analyst categorizes data exfiltration of 50 MB as 'low...
A junior analyst notes that a DNS query for 'malicious-c2-domain.ru'...
A junior analyst reports that 200 failed SSH login attempts against a...
A junior analyst dismisses an alert for unsigned executable running...
A junior analyst classifies an internal user account with failed login...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!