Select one answer for each question. Correct answers and explanations remain hidden until the full test is submitted.
Completion
0 / 25
25 questions remaining.
Assessment Safety Boundary
Every organization, source, field, identity, service, event, alert, test, owner, date, decision, and outcome in this assessment is fictional. The questions do not authorize access, monitoring, testing, scanning, investigation, configuration, or changes to any real system.
1Detection Purpose
What is the strongest starting point for a fictional detection engineering project?
2Defender Questions
Which fictional defender question is most appropriately bounded?
3Telemetry
Which statement best describes useful fictional detection telemetry?
4Source Health
A required fictional group-membership source is delayed. What is the strongest detection behavior?
5Logic Concepts
What should a fictional detection logic narrative include?
6Behavior-Based Detection
Which fictional behavior-based conclusion is strongest?
7Expected Behavior
Why might a fictional approved activity remain visible as an Expected alert?
8False Positives
A fictional alert fires because extension evidence arrived late even though the extension was valid. Which label is strongest after review?
9False Negatives
Why is a quiet fictional period not automatically a true negative?
10Quality Metrics
Why can a large reduction in fictional alert volume be misleading?
11Unknown Outcomes
Two required fictional sources conflict and the available evidence cannot resolve the case. Which outcome is most responsible?
12Detection Tuning
Which fictional tuning change is safest for repeated valid-extension alerts?
13Exceptions
Which fictional exception is best governed?
14Severity and Confidence
Why should fictional severity and confidence be documented separately?
15Alert Mapping
What makes a fictional alert decision-ready?
16Evidence Requests
Which fictional evidence request is most privacy-aware?
17Closure
Which fictional closure criterion is strongest?
18Safe Testing
What is the safest source for A5 fictional detection test data?
19Expected Test Outcomes
Why should fictional expected outcomes be defined before a test is reviewed?
20Boundary Testing
Which fictional test best evaluates an expiration boundary?
21Recovery Testing
A fictional source returns after a blind period and replays queued records. What should the test evaluate?
22Documentation
What should appear first in a strong fictional detection specification?
23Traceability
Why should fictional requirements be linked to tests, alerts, changes, and owners?
24Readiness
When should a fictional detection program remain Conditional?
25Portfolio Safety
Which approach is safest for a public Detection Engineering portfolio?
0 of 25 questions answered
Answers and explanations appear only after submission.