High School AdvancedModule A525-Question AssessmentHidden Answers until Submission

A5 Module Test: Detection Engineering

Demonstrate your understanding of detection goals, telemetry, source health, logic, behavior, quality, tuning, defender questions, safe fake-data testing, documentation, governance, privacy, and lifecycle.

Test Instructions

Answer All 25 Questions before Submitting

Select one answer for each question. Correct answers and explanations remain hidden until the full test is submitted.

Completion

0 / 25

25 questions remaining.

Assessment Safety Boundary

Every organization, source, field, identity, service, event, alert, test, owner, date, decision, and outcome in this assessment is fictional. The questions do not authorize access, monitoring, testing, scanning, investigation, configuration, or changes to any real system.

1Detection Purpose

What is the strongest starting point for a fictional detection engineering project?

2Defender Questions

Which fictional defender question is most appropriately bounded?

3Telemetry

Which statement best describes useful fictional detection telemetry?

4Source Health

A required fictional group-membership source is delayed. What is the strongest detection behavior?

5Logic Concepts

What should a fictional detection logic narrative include?

6Behavior-Based Detection

Which fictional behavior-based conclusion is strongest?

7Expected Behavior

Why might a fictional approved activity remain visible as an Expected alert?

8False Positives

A fictional alert fires because extension evidence arrived late even though the extension was valid. Which label is strongest after review?

9False Negatives

Why is a quiet fictional period not automatically a true negative?

10Quality Metrics

Why can a large reduction in fictional alert volume be misleading?

11Unknown Outcomes

Two required fictional sources conflict and the available evidence cannot resolve the case. Which outcome is most responsible?

12Detection Tuning

Which fictional tuning change is safest for repeated valid-extension alerts?

13Exceptions

Which fictional exception is best governed?

14Severity and Confidence

Why should fictional severity and confidence be documented separately?

15Alert Mapping

What makes a fictional alert decision-ready?

16Evidence Requests

Which fictional evidence request is most privacy-aware?

17Closure

Which fictional closure criterion is strongest?

18Safe Testing

What is the safest source for A5 fictional detection test data?

19Expected Test Outcomes

Why should fictional expected outcomes be defined before a test is reviewed?

20Boundary Testing

Which fictional test best evaluates an expiration boundary?

21Recovery Testing

A fictional source returns after a blind period and replays queued records. What should the test evaluate?

22Documentation

What should appear first in a strong fictional detection specification?

23Traceability

Why should fictional requirements be linked to tests, alerts, changes, and owners?

24Readiness

When should a fictional detection program remain Conditional?

25Portfolio Safety

Which approach is safest for a public Detection Engineering portfolio?

0 of 25 questions answered

Answers and explanations appear only after submission.