100+ Free PSAA Practice Questions
Prepare for the Practical SOC Analyst Associate (PSAA) exam with instant access — no signup required.
Loading practice questions...
Explore More TCM Security Practical Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: PSAA Exam
$249
Exam Cost (incl. course)
TCM Security
2 days
Practical Assessment Window
TCM Security
2 days
Incident Report Submission
TCM Security
30+ hours
SOC 101 Course Length
TCM Security
Lifetime
Certification Validity
TCM Security
1 free
Retake Included
TCM Security
The PSAA (Practical SOC Analyst Associate) is TCM Security's entry-level blue team certification. The 2-day practical exam simulates real SOC work—analyzing phishing emails, network packet captures, SIEM alerts, and EDR telemetry—followed by a 2-day window to submit an incident report. It costs $249 (includes SOC 101 course access and one free retake) and does not expire. This 100-question practice bank prepares candidates with testable knowledge from all PSAA domains.
Sample PSAA Practice Questions
Try these sample questions to test your PSAA exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1When analyzing an email for phishing indicators, which header field most reliably reveals the actual sending mail server's IP address?
2An email passes SPF checks but fails DMARC. Which scenario best explains this?
3A SOC analyst receives a suspicious email with a URL: https://paypa1-secure.login.example.com/verify. What phishing technique does this URL demonstrate?
4Which tool is specifically designed to detonate suspicious email attachments in an isolated environment to observe malicious behavior without risking production systems?
5During phishing triage, an analyst finds the sender domain was registered 2 days ago. Why is this significant?
6A Wireshark capture shows a host making hundreds of DNS queries per minute to a single domain with long random-looking subdomains (e.g., a1b2c3d4e5.evil.com). What activity does this most likely indicate?
7Which Wireshark display filter would isolate only HTTP POST requests from captured traffic?
8An analyst observes repeated TCP SYN packets from one external IP to multiple ports on an internal host with no SYN-ACK responses. What does this pattern indicate?
9In network traffic analysis, what characteristic best identifies beaconing behavior associated with C2 communication?
10What does the Wireshark 'Follow TCP Stream' feature allow an analyst to do?
About the PSAA Exam
The PSAA (Practical SOC Analyst Associate) is TCM Security's entry-level blue team certification. Unlike multiple-choice exams, the PSAA is a hands-on 2-day SOC simulation where candidates investigate realistic security incidents across phishing, network traffic, SIEM, and endpoint telemetry, then write a professional incident report. This practice bank covers the knowledge needed: phishing analysis, Wireshark, Windows Event Logs, SIEM correlation, EDR investigation, threat intel, MITRE ATT&CK, and basic DFIR.
Assessment
Performance-based assessment
Time Limit
2 days practical assessment + 2 days report
Passing Score
Not published
Exam Fee
$249 (TCM Security)
PSAA Exam Content Outline
Phishing Email Analysis & Triage
Email header inspection, SPF/DKIM/DMARC authentication, URL and attachment analysis, IOC extraction, and phishing techniques (typosquatting, subdomain spoofing, homograph attacks)
Network Traffic Analysis
Wireshark display filters and TCP stream reconstruction, C2 beacon detection, DNS tunneling, port scan identification, ICMP tunneling, and protocol-level anomaly investigation
Security Monitoring & Alert Triage
SOC tier responsibilities, true/false positive classification, alert escalation procedures, playbook-driven investigation, NIST SP 800-61 and SANS PICERL lifecycle phases
SIEM & Log Correlation
Windows Event IDs (4624/4625/4688/4698/7045), Splunk SPL queries, correlation rule design, alert fatigue management, and multi-source log investigation for lateral movement and persistence
EDR & Endpoint Security
Process tree analysis, registry persistence detection, living-off-the-land techniques (certutil, mshta, PowerShell -enc), lsass protection, ransomware pre-encryption indicators, and containment actions
Threat Intelligence & IOCs
IOC types and enrichment (VirusTotal, AbuseIPDB, Shodan, URLScan.io), MITRE ATT&CK tactics/techniques, STIX/TAXII, Pyramid of Pain, TIP platforms, and TTP-based detection strategy
Digital Forensics Basics & Incident Documentation
Order of volatility, forensic imaging and chain of custody, Windows triage commands (tasklist, netstat, route print), Linux triage (ss -tunap), Prefetch analysis, mutex artifacts, and incident report writing
How to Pass the PSAA Exam
What You Need to Know
- Passing score: Not published
- Assessment: Performance-based assessment
- Time limit: 2 days practical assessment + 2 days report
- Exam fee: $249
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
PSAA Study Tips from Top Performers
Frequently Asked Questions
What is the PSAA exam format?
The PSAA is a practical hands-on SOC simulation, not a multiple-choice exam. Candidates have 2 full days to complete a realistic SOC assessment investigating security events (phishing emails, network traffic, SIEM alerts, endpoint telemetry), followed by 2 additional days to write and submit a professional incident report. TCM Security assesses candidates on their ability to use analysis tools, interpret artifacts, and apply investigation methodologies.
What does the PSAA exam cost?
The PSAA costs $249, which includes the exam voucher and 12 months of access to TCM Security's SOC 101 course (30+ hours of training). One free retake is included with every voucher. TCM Security also offers a 20% discount for military, veterans, students, teachers, and first responders.
What course should I take to prepare for the PSAA?
TCM Security's Security Operations (SOC) 101 course is the primary preparation pathway and is included with the PSAA voucher. The course provides 30+ hours of practical training covering phishing analysis, network traffic analysis, SIEM operations, endpoint security, threat intelligence, and DFIR fundamentals. The course includes quizzes, written references, and practical exercises.
What skills does the PSAA assess?
The PSAA assesses: phishing email analysis (headers, authentication, URLs, attachments); network traffic analysis (Wireshark, PCAP); security alert triage and escalation (Tier 1/2 SOC workflows); SIEM and log correlation (Windows Event Logs, Splunk); EDR tool usage; threat intelligence enrichment (VirusTotal, IOCs, MITRE ATT&CK); and professional incident report writing.
Does the PSAA certification expire?
No — TCM Security certifications do not expire. Once you pass the PSAA, the certification is yours for life.
Is this practice bank like the real PSAA exam?
No — the real PSAA is a hands-on practical assessment; this is a multiple-choice knowledge-prep bank. However, this bank covers all the conceptual knowledge required to perform well in the practical exam: understanding what tools to use, how protocols work, what indicators mean, and how to apply SOC methodology. Pair this with hands-on practice (TCM SOC 101 labs, TryHackMe, or Blue Team Labs Online) for complete preparation.