312-39 Exam Questions
194 real 312-39 exam questions with expert-verified answers and explanations. Page 3 of 4.
- Question #103
Which one of the following is the correct flow for Setting Up a Computer Forensics Lab?
- Question #104
Which of the following directory will contain logs related to printer access?
- Question #105
Which of the following command is used to enable logging in iptables?
- Question #106
Ray is a SOC analyst in a company named Queens Tech. One Day, Queens Tech is affected by a DoS/DDoS attack. For the containment of this incident, Ray and his team are trying to pro...
- Question #107
Identify the attack when an attacker by several trial and error can read the contents of a password file present in the restricted etc folder just by manipulating the URL in the br...
- Question #108
Which encoding replaces unusual ASCII characters with "%" followed by the character's two-digit ASCII code expressed in hexadecimal?
- Question #109
Which of the following formula represents the risk?
- Question #110
The Syslog message severity levels are labelled from level 0 to level 7. What does level 0 indicate?
- Question #111
Where will you find the reputation IP database, if you want to monitor traffic from known bad IP reputation using OSSIM SIEM?
- Question #112
According to the Risk Matrix table, what will be the risk level when the probability of an attack is very low and the impact of that attack is major?
- Question #114
Which of the following technique involves scanning the headers of IP packets leaving a network to make sure that the unauthorized or malicious traffic never leaves the internal net...
- Question #115
Which of the following formula is used to calculate the EPS of the organization?
- Question #116
Juliea a SOC analyst, while monitoring logs, noticed large TXT, NULL payloads. What does this indicate?
- Question #117SOC Fundamentals and Operations
An organization is implementing and deploying the SIEM with following capabilities. What kind of SIEM deployment architecture the organization is planning to implement?
SIEM deployment modelsself-hosted infrastructureself-managed operationsSOC architecture - Question #118
What is the process of monitoring and capturing all data packets passing through a given network using different tools?
- Question #119
Which of the following is a report writing tool that will help incident handlers to generate efficient reports on detected incidents during incident response process?
- Question #120
Which of the following Windows features is used to enable Security Auditing in Windows?
- Question #121
Which of the following attack can be eradicated by filtering improper XML syntax?
- Question #122
Which of the following attack can be eradicated by using a safe API to avoid the use of the interpreter entirely?
- Question #123
Shawn is a security manager working at Lee Inc Solution. His organization wants to develop threat intelligent strategy plan. As a part of threat intelligent strategy plan, he sugge...
- Question #124
Which of the following can help you eliminate the burden of investigating false positives?
- Question #125
Which of the following event detection techniques uses User and Entity Behavior Analytics (UEBA)?
- Question #126
Identify the password cracking attempt involving a precomputed dictionary of plaintext passwords and their corresponding hash values to crack the password.
- Question #127
Which of the log storage method arranges event logs in the form of a circular buffer?
- Question #128
An organization wants to implement a SIEM deployment architecture. However, they have the capability to do only log collection and the rest of the SIEM functions must be managed by...
- Question #129
Banter is a threat analyst in Christine Group of Industries. As a part of the job, he is currently formatting and structuring the raw data. He is at which stage of the threat intel...
- Question #130Security Incident Detection
Which of the following attacks causes sudden changes in file extensions or increase in file renames at rapid speed?
RansomwareMalware DetectionFile System BehaviorAttack Indicators - Question #131
Which of the following security technology is used to attract and trap people who attempt unauthorized or illicit utilization of the host system?
- Question #133
Which of the following factors determine the choice of SIEM architecture?
- Question #134
What does HTTPS Status code 403 represents?
- Question #135
Which of the following Windows event is logged every time when a user tries to access the "Registry" key?
- Question #136
Which of the following are the responsibilities of SIEM Agents? 1. Collecting data received from various devices sending data to SIEM before forwarding it to the central engine. 2....
- Question #137
Sam, a security analyst with INFOSOL INC., while monitoring and analyzing IIS logs, detected an event matching regex /\\w*((\%27)|(\'))((\%6F)|o|(\%4F))((\%72)|r|(\%52))/ix. What d...
- Question #138
Which of the following framework describes the essential characteristics of an organization's security engineering process that must exist to ensure good security engineering?
- Question #139
What does Windows event ID 4740 indicate?
- Question #140
Which of the following is a Threat Intelligence Platform?
- Question #141
A type of threat intelligent that find out the information about the attacker by misleading them is known as .
- Question #142
Chloe, a SOC analyst with Jake Tech, is checking Linux systems logs. She is investigating files at /var/log/ wtmp. What Chloe is looking at?
- Question #143
Which of the following threat intelligence is used by a SIEM for supplying the analysts with context and "situational awareness" by using threat actor TTPs, malware campaigns, tool...
- Question #144
Properly applied cyber threat intelligence to the SOC team help them in discovering TTPs. What does these TTPs refer to?
- Question #145
Which of the following data source can be used to detect the traffic associated with Bad Bot User- Agents?
- Question #146
Daniel is a member of an IRT, which was started recently in a company named Mesh Tech. He wanted to find the purpose and scope of the planned incident response capabilities. What i...
- Question #147
John, a SOC analyst, while monitoring and analyzing Apache web server logs, identified an event log matching Regex /(\.|(%|%25)2E)(\.|(%|%25)2E)(\/|(%|%25)2F|\\|(%|%25)5C)/i. What...
- Question #148
According to the Risk Matrix table, what will be the risk level when the probability of an attack is very high, and the impact of that attack is major? NOTE: It is mandatory to ans...
- Question #149
Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry: May 06 2018 21:27:27 asa 1: %ASA -5 - 11008: User 'enable...
- Question #150
What is the correct sequence of SOC Workflow?
- Question #151
Wesley is an incident handler in a company named Maddison Tech. One day, he was learning techniques for eradicating the insecure deserialization attacks. What among the following s...
- Question #152
An attacker, in an attempt to exploit the vulnerability in the dynamically generated welcome page, inserted code at the end of the company's URL as follows: error");</script>. Iden...
- Question #153
Which of the following formula represents the risk levels?
- Question #154
In which of the following incident handling and response stages, the root cause of the incident must be found from the forensic results?