What is the primary objective of a "Tier 1" analyst during the triage process?
A.
Performing deep-dive memory forensics on a compromised server.
B.
Negotiating with ransomware actors to recover encrypted data.
C.
Determining the validity of an alert and its urgency for escalation.
D.
Rewriting the company's information security policy.
The Answer Is:
C
This question includes an explanation.
Explanation:
In the standard SOC hierarchy, the Tier 1 Analyst (Triage Specialist) acts as the first filter for all incoming security telemetry.
Validation: Their goal is to quickly distinguish between True Positives (real threats) and False Positives (benign activity flagged as a threat).
Prioritization: Once a threat is validated, they must determine its Severity (how bad it is) and Urgency (how fast we need to act). If the incident is complex or high-risk, they escalate it to Tier 2 (Incident Responders) for mitigation.
Efficiency: This role is critical for ensuring that highly skilled Tier 2 and Tier 3 analysts are only spending their time on confirmed, significant threats.
SecOps-Pro PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"