312-39 Exam Questions
194 real 312-39 exam questions with expert-verified answers and explanations. Page 3 of 4.
- Question #103Security Incident Response
Which one of the following is the correct flow for Setting Up a Computer Forensics Lab?
forensics lab setuplab planningphysical designbudgeting - Question #104SOC Fundamentals and Operations
Which of the following directory will contain logs related to printer access?
Linux logsCUPS log pathprinter access loglog management - Question #105SOC Fundamentals and Operations
Which of the following command is used to enable logging in iptables?
iptables loggingLinux firewalllog enablementcommand syntax - Question #106Security Incident Response
Ray is a SOC analyst in a company named Queens Tech. One Day, Queens Tech is affected by a DoS/DDoS attack. For the containment of this incident, Ray and his team are trying to pro...
DDoS mitigationattack absorptionbandwidth scalingDoS response - Question #107Security Incident Detection
Identify the attack when an attacker by several trial and error can read the contents of a password file present in the restricted etc folder just by manipulating the URL in the br...
directory traversalweb application attacksURL manipulationpath traversal - Question #108SOC Fundamentals and Operations
Which encoding replaces unusual ASCII characters with "%" followed by the character's two-digit ASCII code expressed in hexadecimal?
URL encodingpercent encodingASCII hex encodingweb encoding - Question #109Compliance and Auditing
Which of the following formula represents the risk?
risk formularisk calculationasset valuelikelihood impact - Question #110SOC Fundamentals and Operations
The Syslog message severity levels are labelled from level 0 to level 7. What does level 0 indicate?
syslog severitylog levelsemergency levelsyslog standard - Question #111SOC Fundamentals and Operations
Where will you find the reputation IP database, if you want to monitor traffic from known bad IP reputation using OSSIM SIEM?
OSSIM SIEMIP reputation databaseSIEM configurationthreat intelligence feeds - Question #112Compliance and Auditing
According to the Risk Matrix table, what will be the risk level when the probability of an attack is very low and the impact of that attack is major?
risk matrixprobability impactrisk assessmentrisk rating - Question #114SOC Fundamentals and Operations
Which of the following technique involves scanning the headers of IP packets leaving a network to make sure that the unauthorized or malicious traffic never leaves the internal net...
egress filteringoutbound trafficpacket header inspectionnetwork filtering - Question #115SOC Fundamentals and Operations
Which of the following formula is used to calculate the EPS of the organization?
EPS formulaevents per secondSIEM metricslog throughput - Question #116Security Incident Detection
Juliea a SOC analyst, while monitoring logs, noticed large TXT, NULL payloads. What does this indicate?
DNS exfiltrationlarge TXT recordsNULL payloaddata exfiltration detection - Question #117SOC Fundamentals and Operations
An organization is implementing and deploying the SIEM with following capabilities. What kind of SIEM deployment architecture the organization is planning to implement?
SIEM deployment modelsself-hosted infrastructureself-managed operationsSOC architecture - Question #118SOC Fundamentals and Operations
What is the process of monitoring and capturing all data packets passing through a given network using different tools?
network sniffingpacket capturetraffic monitoringnetwork analysis - Question #119Reporting and Communication
Which of the following is a report writing tool that will help incident handlers to generate efficient reports on detected incidents during incident response process?
MagicTreeincident reporting toolreport generationIR documentation - Question #120Compliance and Auditing
Which of the following Windows features is used to enable Security Auditing in Windows?
Windows security auditingLocal Group Policy Editoraudit policyWindows hardening - Question #121Security Incident Detection
Which of the following attack can be eradicated by filtering improper XML syntax?
web services attacksXML injectionimproper XML syntaxinput filtering - Question #122SOC Fundamentals and Operations
Which of the following attack can be eradicated by using a safe API to avoid the use of the interpreter entirely?
command injectioninjection attackssafe APIinput validation - Question #123Threat Intelligence
Shawn is a security manager working at Lee Inc Solution. His organization wants to develop threat intelligent strategy plan. As a part of threat intelligent strategy plan, he sugge...
threat intelligence strategyintelligence planningthreat trendingTI lifecycle - Question #124SOC Fundamentals and Operations
Which of the following can help you eliminate the burden of investigating false positives?
false positivescontext dataalert managementSIEM - Question #125Security Incident Detection
Which of the following event detection techniques uses User and Entity Behavior Analytics (UEBA)?
UEBAanomaly detectionbehavioral analyticsevent detection techniques - Question #126Security Incident Detection
Identify the password cracking attempt involving a precomputed dictionary of plaintext passwords and their corresponding hash values to crack the password.
rainbow tablepassword crackinghash valuesprecomputed dictionary - Question #127SOC Fundamentals and Operations
Which of the log storage method arranges event logs in the form of a circular buffer?
log storagecircular bufferwrappingFIFO - Question #128SOC Fundamentals and Operations
An organization wants to implement a SIEM deployment architecture. However, they have the capability to do only log collection and the rest of the SIEM functions must be managed by...
SIEM deploymentMSSPself-hosted architecturelog collection - Question #129Threat Intelligence
Banter is a threat analyst in Christine Group of Industries. As a part of the job, he is currently formatting and structuring the raw data. He is at which stage of the threat intel...
threat intelligence lifecycleprocessing and exploitationdata formattingraw data - Question #130Security Incident Detection
Which of the following attacks causes sudden changes in file extensions or increase in file renames at rapid speed?
RansomwareMalware DetectionFile System BehaviorAttack Indicators - Question #131SOC Fundamentals and Operations
Which of the following security technology is used to attract and trap people who attempt unauthorized or illicit utilization of the host system?
honeypotdeception technologyunauthorized accesssecurity controls - Question #133SOC Fundamentals and Operations
Which of the following factors determine the choice of SIEM architecture?
SIEM architecturenetwork topologydeployment factors - Question #134SOC Fundamentals and Operations
What does HTTPS Status code 403 represents?
HTTP status codes403 forbiddenweb server response - Question #135Security Incident Detection
Which of the following Windows event is logged every time when a user tries to access the "Registry" key?
Windows event ID 4657registry key accessaudit loggingWindows monitoring - Question #136SOC Fundamentals and Operations
Which of the following are the responsibilities of SIEM Agents? 1. Collecting data received from various devices sending data to SIEM before forwarding it to the central engine. 2....
SIEM agentsdata collectiondata normalizationlog forwarding - Question #137Security Incident Detection
Sam, a security analyst with INFOSOL INC., while monitoring and analyzing IIS logs, detected an event matching regex /\\w*((\%27)|(\'))((\%6F)|o|(\%4F))((\%72)|r|(\%52))/ix. What d...
SQL injectionIIS log analysisregex pattern detectionweb attack detection - Question #138Compliance and Auditing
Which of the following framework describes the essential characteristics of an organization's security engineering process that must exist to ensure good security engineering?
SSE-CMMsecurity engineering frameworkprocess maturitysecurity standards - Question #139Security Incident Detection
What does Windows event ID 4740 indicate?
Windows event ID 4740account lockoutuser account monitoringWindows security events - Question #140Threat Intelligence
Which of the following is a Threat Intelligence Platform?
threat intelligence platformTIP toolsthreat intelligence feeds - Question #141Threat Intelligence
A type of threat intelligent that find out the information about the attacker by misleading them is known as .
counter intelligencethreat intelligence typesattacker deceptionoperational intelligence - Question #142Security Incident Detection
Chloe, a SOC analyst with Jake Tech, is checking Linux systems logs. She is investigating files at /var/log/ wtmp. What Chloe is looking at?
Linux logswtmplogin records/var/log - Question #143Threat Intelligence
Which of the following threat intelligence is used by a SIEM for supplying the analysts with context and "situational awareness" by using threat actor TTPs, malware campaigns, tool...
threat intelligence typesSIEMtactical intelligenceoperational intelligence - Question #144Threat Intelligence
Properly applied cyber threat intelligence to the SOC team help them in discovering TTPs. What does these TTPs refer to?
TTPsthreat intelligence terminologySOC fundamentals - Question #145Security Incident Detection
Which of the following data source can be used to detect the traffic associated with Bad Bot User- Agents?
web server logsbad bot detectionlog sourcesuser-agent analysis - Question #146Security Incident Response
Daniel is a member of an IRT, which was started recently in a company named Mesh Tech. He wanted to find the purpose and scope of the planned incident response capabilities. What i...
incident response missionIRT purposeIR planningscope definition - Question #147Security Incident Detection
John, a SOC analyst, while monitoring and analyzing Apache web server logs, identified an event log matching Regex /(\.|(%|%25)2E)(\.|(%|%25)2E)(\/|(%|%25)2F|\\|(%|%25)5C)/i. What...
directory traversalweb server logsregex detectionApache logs - Question #148SOC Fundamentals and Operations
According to the Risk Matrix table, what will be the risk level when the probability of an attack is very high, and the impact of that attack is major? NOTE: It is mandatory to ans...
risk matrixrisk levelsprobability vs impactrisk assessment - Question #149Security Incident Detection
Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry: May 06 2018 21:27:27 asa 1: %ASA -5 - 11008: User 'enable...
Cisco ASA logssyslog severity levelsfirewall log analysislog interpretation - Question #150SOC Fundamentals and Operations
What is the correct sequence of SOC Workflow?
SOC workflowincident handling sequenceSOC operations - Question #151Security Incident Response
Wesley is an incident handler in a company named Maddison Tech. One day, he was learning techniques for eradicating the insecure deserialization attacks. What among the following s...
insecure deserializationeradication techniquessecure codingserialization security - Question #152Security Incident Detection
An attacker, in an attempt to exploit the vulnerability in the dynamically generated welcome page, inserted code at the end of the company's URL as follows: error");</script>. Iden...
XSS attackcross-site scriptingweb application attacksURL injection - Question #153SOC Fundamentals and Operations
Which of the following formula represents the risk levels?
risk formularisk calculationconsequence vs likelihoodrisk management - Question #154Security Incident Response
In which of the following incident handling and response stages, the root cause of the incident must be found from the forensic results?
incident response stageseradicationroot cause analysisforensics