Practice SOC incident triage vocabulary: true positives, escalation levels, alert fatigue, suppression rules, and triage decision trees.
0 / 10 completed
1 / 10
An analyst says 'the alert is a true positive — escalating to SEV-2'. What does 'true positive' mean?
A true positive means the detection rule fired AND a real threat or malicious activity is confirmed. The analyst then escalates based on severity — SEV-2 indicates a serious incident requiring prompt response.
2 / 10
What is 'alert fatigue' in a SOC context?
Alert fatigue occurs when analysts are overwhelmed by large volumes of low-quality or false-positive alerts. Over time they may start ignoring or quickly closing alerts without proper investigation, increasing risk of missing real threats.
3 / 10
A team lead says 'we suppressed the noisy rule'. What did they do?
Suppressing a noisy rule means adding an exclusion or tuning condition so that known benign events matching the rule no longer generate alerts. This reduces noise without deleting the rule entirely.
4 / 10
'The analyst triages 50 alerts per shift.' In this context, what does triage mean?
Triage in a SOC means rapidly assessing incoming alerts to classify them (true positive, false positive, benign) and decide the appropriate response — escalate, close, investigate further, or suppress.
5 / 10
What is a 'triage decision tree' in SOC operations?
A triage decision tree is a structured guide — often a flowchart — that walks an analyst through a series of yes/no questions to consistently classify alerts and determine the correct response action, reducing analyst-to-analyst variability.
6 / 10
Sarah from the Security Operations team sent this Slack message: 'Just triaged a spike of alerts related to unusual outbound connections. Looks like a misconfigured dev environment briefly hitting our external API – low impact, marking as resolved.' What does 'marking as resolved' imply in this situation?
'Marking as resolved' in incident response doesn't necessarily mean the underlying cause is gone. It indicates that, based on the initial assessment, the alert no longer represents an immediate risk. A common misconception is that 'resolved' always means a threat was found; it simply means the *alert* is considered closed for now – further monitoring might still be needed.
7 / 10
You're reviewing a pull request for a new microservice. The developer includes this comment in the code: 'Adding logging to track all outbound API calls – crucial for future triage of potential data breaches.' What is the primary purpose of this logging action in relation to incident triage?
The phrase 'crucial for future triage' highlights the logging's role in incident investigation. Triage involves quickly assessing and prioritizing incidents; detailed logs allow analysts to reconstruct events, identify root causes, and determine the severity of a potential issue – specifically when related to API calls. Logging isn't primarily about performance or deployment.
8 / 10
During a daily standup, the DevOps engineer says: 'We've implemented a new rule in our SIEM to automatically suppress alerts from our staging environment. It's a bit noisy and doesn't contribute to actual incident investigation.' What is the primary reason for suppressing this alert?
Suppressing an alert isn't about reducing overall alert volume; it's a targeted action. The engineer is recognizing that the rule's output is 'noisy' – meaning it generates alerts that don't contribute to effective incident investigation. This indicates the rule needs adjustment or removal to avoid diverting resources.
9 / 10
You are reviewing a pull request description for an update to the incident management system's API. The developer includes this text: 'Implemented endpoint to retrieve historical alert data by severity and timestamp – enabling automated triage workflows.' What is the most important benefit of this API change in terms of incident response?
The core benefit is 'enabling automated triage workflows.' Automated triage relies on systems being able to *categorize and prioritize* alerts based on their attributes (severity, timestamp). This API change facilitates this automation by providing structured data for the system to process – a crucial element of efficient incident response.
10 / 10
A SOC analyst is describing their approach during an incident: 'I'm using a triage decision tree to quickly assess the impact of each alert. It starts with verifying the source and severity, then determines if user activity is involved before escalating.' What does a 'triage decision tree' represent?
A triage decision tree is precisely a flowchart – it's a visual guide. It provides a structured approach for analysts to systematically evaluate alerts, starting with basic checks (source, severity) and progressively narrowing down the potential impact of an incident. This facilitates rapid prioritization and appropriate escalation.
What will I learn from the "Incident Triage Vocabulary" exercise?
Practice SOC incident triage vocabulary: true positives, escalation levels, alert fatigue, suppression rules, and triage decision trees.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall required.
How many questions are in this exercise?
This set contains 10 multiple-choice questions, each with a detailed explanation shown after you answer.
Do I need to create an account to track my progress?
No account is required. Your progress bar and score reset each time you reload the page, but you can retry the exercise as many times as you like.
Who is this SOC Operations Language exercise for?
This exercise is built for IT professionals and non-native English speakers who need to read, write, and discuss soc operations language topics confidently at work.
What happens if I answer a question incorrectly?
You will see the correct answer highlighted along with a detailed explanation of why it is correct -- so every wrong answer becomes a learning moment, not just a lost point.
Can I retry this exercise?
Yes -- click "Try again" on the results screen at any time to reset your score and go through all the questions again.
How long does this exercise take to complete?
Most learners finish all 10 questions in under 10 minutes, since each question is answered by clicking a single option.
Where can I find more SOC Operations Language exercises?
See the full SOC Operations Language exercises hub for more vocabulary drills on this topic.
Is this exercise mobile-friendly?
Yes -- the exercise works on any device with a modern browser, including phones and tablets, with no app download required.