Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsHard
A small business has decided to implement a Security Operations Center (SOC) to proactively monitor for threats. Due to budget and staffing constraints, they are exploring options where they can leverage external expertise for 24/7 monitoring and initial triage, while retaining control over critical incident response decisions and long-term security strategy. Which SOC model would be most appropriate for this business?
- AVirtual SOC
- BCentralized SOC
- COutsourced (Managed) SOC
- DCo-managed SOC
Show answer & explanationAnswer & explanation
Correct answer: D. Co-managed SOC
A co-managed SOC model allows an organization to partner with a Managed Security Service Provider (MSSP) for 24/7 monitoring and initial incident handling, while the internal team retains ownership of strategic decisions, advanced investigations, and full incident response, which perfectly fits the business's constraints and requirements.
Why the other options are wrong
- A. A virtual SOC still implies internal staff performing functions, which might not solve the 24/7 monitoring and staffing constraints.
- B. A centralized SOC requires significant internal resources, which the business lacks.
- C. An fully outsourced SOC delegates almost all security operations, which contradicts the desire to retain control over critical decisions.
Co-managed SOC Model
A hybrid Security Operations Center model where an organization partners with a Managed Security Service Provider (MSSP) to share security monitoring and incident response responsibilities, balancing internal control with external expertise.
- Internal team retains strategic control and advanced response.
- MSSP provides 24/7 monitoring, initial triage, and expertise.
- Ideal for organizations with budget/staffing constraints but desire for control.
Memory trick: Need help but want control? Co-manage!