High School IntermediatePractice Test 250 Applied Questions

Intermediate Practice Test 2

Complete fifty mixed fictional scenarios focused on evidence analysis, case boundaries, applied defensive decisions, ownership, service continuity, impact limits, communication, validation, residual risk, and portfolio reasoning across the full Intermediate track.

Readiness Check

Before You Begin

0/5 ready

Practice Test Instructions

Use Applied Evidence-Based Reasoning

Read the boundary

Identify the fictional system, identity, source, time window, owner, service, action, and evidence limit.

Compare the options

Prefer the answer that is proportionate, authorized, reversible, service-aware, measurable, and evidence-limited.

Review the pattern

Record repeated errors in case structure, impact language, ownership, communication, validation, or residual risk.

Many questions include one technically possible answer and one professionally stronger answer. Choose the response that best preserves evidence, authority, safety, continuity, and validation.

Check Your Understanding

Intermediate Practice Test 2

Choose your answers first. Explanations appear only after submission.

1. A fictional SOC dashboard groups a supplier sign-in, cloud policy change, phishing click, and web authorization alert into one incident because they occurred within forty minutes. What is the strongest first decision?

2. A fictional workstation connects to a server on an uncommon port immediately after an approved software update. Which evidence should be reviewed first?

3. A fictional network sensor reports repeated denied connections from one internal device. Which conclusion is strongest?

4. A fictional Linux service account owns a new file in a protected directory. What is the strongest next step?

5. A fictional Linux log shows three failed service starts followed by one successful start after maintenance. What does this prove?

6. A fictional Windows endpoint creates a scheduled task under a known service account outside the normal patch window. Which response is strongest?

7. A fictional Windows security setting shows the intended value in the configuration tool, but the service still behaves as before. What should the defender conclude?

8. A fictional alert was generated at 10:40, but the underlying event occurred at 10:05 and was collected at 10:38. Which time belongs first in the incident sequence?

9. A fictional log source reports healthy delivery, but a second source covering the same service stops reporting. What is the strongest statement?

10. A fictional detection rule fires on approved administrator activity every morning. What is the strongest improvement?

11. A fictional tool vendor claims its alert proves account compromise. What should the analyst do?

12. A fictional supplier account is still active because an old ticket says permanent access. The service owner says the project ended. What is the strongest decision?

13. A fictional user has no direct privileged role but can reach an administrative resource through a nested group. What does this demonstrate?

14. A fictional emergency account remains enabled two weeks after the emergency ended. What is the strongest recommendation?

15. A fictional email is malicious with high confidence, but no user clicked it. Which action is proportionate?

16. A fictional user clicked a suspicious link and later completed a successful sign-in from the usual device and location. What is the strongest conclusion?

17. A fictional web application blocks one test input but accepts a related encoded form. What does this suggest?

18. A fictional support role can view a manager page but cannot submit changes. Which impact statement is strongest?

19. A fictional code review finds authorization checks repeated differently across several routes. Which recommendation is strongest?

20. A fictional vulnerability scanner reports critical severity on a system isolated from users and protected by strong controls. What should happen next?

21. A fictional medium-severity issue affects an internet-facing identity service with weak monitoring. Why might it receive high priority?

22. A fictional vulnerability cannot be fixed before the maintenance window. What is the strongest temporary plan?

23. A fictional incident commander wants to disable a critical service because one suspicious sign-in occurred. Services are stable and targeted account controls are available. What is the strongest response?

24. A fictional response ticket says containment completed, but the account still has an active session. What is the correct status?

25. A fictional incident report states that no data loss occurred because no loss appears in the reviewed logs. What is missing?

26. A fictional forensic timeline contains two records with conflicting timestamps. Which action is strongest?

27. A fictional analyst receives a copied log excerpt without source details. How should it be used?

28. A fictional cloud provider secures the physical platform, but a customer creates a broad storage policy. Who owns the policy correction?

29. A fictional cloud storage policy is restored, but the source-health monitor remains unhealthy. What is the strongest status?

30. A fictional cloud key is rotated, but an old application still depends on the previous key. What should happen?

31. A fictional policy says privileged access must expire, but no review process or owner is defined. What is the strongest improvement?

32. A fictional risk recommendation proposes monitoring only, even though unsupported privileged access is confirmed. What is the strongest critique?

33. A fictional risk owner accepts a risk without an expiration or review trigger. What is missing?

34. A fictional SOC analyst closes many cases quickly, but several reopen because validation was incomplete. Which metric needs improvement?

35. A fictional shift handoff says only 'continue monitoring.' What is missing?

36. A fictional SOC queue contains one severe but well-contained issue and one moderate issue affecting a critical identity service with weak visibility. What should determine priority?

37. A fictional leadership message includes twenty raw log lines but no decision request. What is the strongest revision?

38. A fictional user notice says 'your account was compromised' after one link click and no confirmed credential entry. What is wrong?

39. A fictional supplier notice says 'contact us if needed' after access removal. What should be added?

40. A fictional architecture diagram shows a solid arrow from a supplier identity to confidential storage based only on shared timing. What is the strongest correction?

41. A fictional diagram uses color alone to distinguish confirmed, possible, and unknown relationships. What should be improved?

42. A fictional portfolio artifact contains every raw record but no learning claim. What is the strongest revision?

43. A fictional portfolio reflection says only 'I learned a lot.' What should be added?

44. A fictional readiness review uses only quiz averages. What is the strongest improvement?

45. A fictional learner repeatedly confuses completed changes with validated outcomes. What is the strongest repair?

46. A fictional learner scores well but misses one nested IAM path and one residual-risk consistency check. What is the strongest readiness conclusion?

47. A fictional capstone contains six cases, all immediate actions are complete, and services are stable. What is still required before monitored follow-up?

48. A fictional final report says one common actor caused all six cases, but no shared identity, session, access path, or evidence supports it. What is the strongest correction?

49. What makes this fictional Practice Test 2 and its related portfolio work safe to share?

50. A fictional analyst finishes Practice Test 2 with several missed questions in evidence limits, ownership, and validation. What is the strongest next step before the Final Test?

Score Guide

Use the Result before the Final Test

46–50 correct

Strong applied readiness. Review every missed explanation and verify that your final portfolio uses the same reasoning.

40–45 correct

Solid applied readiness. Complete focused review of the two or three recurring decision patterns.

32–39 correct

Developing applied readiness. Revisit the related modules, revise artifacts, and complete delayed reassessment.

0–31 correct

Major review needed. Rebuild high-impact concepts before beginning the 125-question Final Test.

Before the Final Test, review the exact reason each missed choice was weaker. Repair the related fictional report, diagram, recommendation, communication, or validation record when the error reflects an applied skill gap.

Key Takeaways

What You Should Remember

1.Applied Intermediate decisions depend on evidence, scope, ownership, context, and validation rather than alert severity alone.
2.Shared timing may justify coordination but does not establish a common cause.
3.Possible exposure, confirmed access, confirmed impact, and residual uncertainty should remain separate.
4.Proportionate defensive actions preserve service whenever targeted reversible controls are sufficient.
5.Audience-specific communication should preserve one approved fictional fact set.
6.Final closure requires validated technical and operational outcomes, not completed tickets or quiet dashboards.

Next Assessment

Continue to the 125-Question Intermediate Final Test

Review recurring mistakes, revise related fictional artifacts, complete delayed reassessment, and confirm that no major safety, ownership, validation, or evidence-boundary gap remains.