312-39 Exam Questions
194 real 312-39 exam questions with expert-verified answers and explanations. Page 4 of 4.
- Question #155Security Incident Detection
Jane, a security analyst, while analyzing IDS logs, detected an event matching Regex /((\%3C)|<)((\%69)|i|(\% 49))((\%6D)|m|(\%4D))((\%67)|g|(\%47))[^\n]+((\%3E)|>)/|. What does th...
XSS detectionIDS log analysisregex pattern matchingimage tag injection - Question #156Security Incident Detection
Which of the following Windows Event Id will help you monitors file sharing across the network?
Windows Event IDfile sharing monitoringevent ID 5140Windows logs - Question #157Threat Intelligence
The threat intelligence, which will help you, understand adversary intent and make informed decision to ensure appropriate security in alignment with risk. What kind of threat inte...
strategic threat intelligenceadversary intentrisk-informed decisionsthreat intelligence types - Question #159Security Incident Detection
Which of the following fields in Windows logs defines the type of event occurred, such as Correlation Hint, Response Time, SQM, WDI Context, and so on?
Windows event log fieldstask categorylog structureevent metadata - Question #160Security Incident Response
Which of the following tool is used to recover from web application incident?
web application incident recoveryIR toolsCrowdStrikeorchestration - Question #161SOC Fundamentals and Operations
Robin, a SOC engineer in a multinational company, is planning to implement a SIEM. He realized that his organization is capable of performing only Correlation, Analytics, Reporting...
SIEM deployment modelshybrid SIEMMSSPmanaged security services - Question #162Security Incident Detection
What type of event is recorded when an application driver loads successfully in Windows?
Windows event typesinformation eventdriver loadingWindows logs - Question #163Security Incident Detection
An attacker exploits the logic validation mechanisms of an e-commerce website. He successfully purchases a product worth $100 for $10 by modifying the URL exchanged between the cli...
parameter tamperingURL manipulatione-commerce attacksweb application security - Question #164Threat Intelligence
John, a threat analyst at GreenTech Solutions, wants to gather information about specific threats against the organization. He started collecting information from various sources,...
operational threat intelligencethreat intelligence typesHUMINTsocial media intelligence - Question #165SOC Fundamentals and Operations
Which of the following is a default directory in a Mac OS X that stores security-related logs?
macOS log directoriessystem logssecurity logslog file paths - Question #166Security Incident Detection
John, SOC analyst wants to monitor the attempt of process creation activities from any of their Windows endpoints. Which of following Splunk query will help him to fetch related lo...
Splunk queriesWindows Event ID 4688process creationSIEM - Question #167SOC Fundamentals and Operations
Harley is working as a SOC analyst with Powell Tech. Powell Inc. is using Internet Information Service (IIS) version 7.0 to host their website. Where will Harley find the web serve...
IIS logsweb server logslog file pathsWindows IIS - Question #168SOC Fundamentals and Operations
What does the Security Log Event ID 4624 of Windows 10 indicate?
Windows Event ID 4624logon eventsWindows security logsevent IDs - Question #169Compliance and Auditing
Which of the following is a set of standard guidelines for ongoing development, enhancement, storage, dissemination and implementation of security standards for account data protec...
PCI-DSScompliance standardspayment card securitydata protection - Question #170SOC Fundamentals and Operations
What does the HTTP status codes 1XX represents?
HTTP status codesinformational responsesweb protocols - Question #171Threat Intelligence
In which phase of Lockheed Martin's - Cyber Kill Chain Methodology, adversary creates a deliverable malicious payload using an exploit and a backdoor?
Cyber Kill ChainweaponizationLockheed Martinattack methodology - Question #172Security Incident Detection
Identify the attack, where an attacker tries to discover all the possible information about a target network before launching a further attack.
reconnaissanceattack typesinformation gatheringnetwork scanning - Question #173SOC Fundamentals and Operations
What does [-n] in the following checkpoint firewall log syntax represents? fw log [-f [-t]] [-n] [-l] [-o] [-c action] [-h host] [-s starttime] [-e endtime] [-b starttime endtime]...
CheckPoint firewall logsfirewall log syntaxDNS resolutionlog analysis - Question #174Security Incident Detection
Which of the following attack inundates DHCP servers with fake DHCP requests to exhaust all available IP addresses?
DHCP starvation attacknetwork attacksIP exhaustionDHCP attacks - Question #175Security Incident Response
Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket raised regarding a handling, at one stage, he has performed incident analysis and validation to che...
incident triagefalse positive validationincident handlingIH&R - Question #176Security Incident Response
Which of the following is a correct flow of the stages in an incident handling and response (IH&R) process?
IH&R process flowincident response stagesincident handling workflow - Question #178SOC Fundamentals and Operations
Peter, a SOC analyst with Spade Systems, is monitoring and analyzing the router logs of the company and wanted to check the logs that are generated by access control list numbered...
Cisco router logsshow logging commandACL logginglog filtering - Question #179Security Incident Detection
Identify the attack in which the attacker exploits a target system through publicly known but still unpatched vulnerabilities.
zero-day attackunpatched vulnerabilitiesexploit typesattack classification - Question #180SOC Fundamentals and Operations
In which log collection mechanism, the system or application sends log records either on the local disk or over the network.
push-based log collectionlog forwardinglog collection mechanismsSIEM - Question #181Security Incident Detection
Which of the following attack can be eradicated by disabling of "allow_url_fopen and allow_url_include" in the php.ini file?
file injection attacksPHP securityallow_url_fopenweb application attacks - Question #182SOC Fundamentals and Operations
Which of the following stage executed after identifying the required event sources?
SIEM use casesevent sourcesuse case developmentSOC workflow - Question #183Security Incident Response
Which of the following steps of incident handling and response process focus on limiting the scope and extent of an incident?
containmentincident scope limitationincident responseIH&R - Question #184Security Incident Detection
Which of the following data source will a SOC Analyst use to monitor connections to the insecure ports?
Netstatport monitoringdata sourcesSOC monitoring - Question #185Security Incident Response
Which of the following technique protects from flooding attacks originated from the valid prefixes (IP addresses) so that they can be traced to its true source?
ingress filteringflooding attacksIP spoofingDDoS protection - Question #186Security Incident Response
Which of the following contains the performance measures, and proper project and time management details?
incident response proceduresIR documentationperformance measurestime management - Question #187Security Incident Detection
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from wher...
SIEM dashboardTOR trafficDHCP logsIP resolution - Question #188Security Incident Response
Which of the following process refers to the discarding of the packets at the routing level without informing the source that the data did not reach its intended recipient?
black hole filteringpacket discardDDoS mitigationrouting - Question #189Security Incident Detection
Which of the following tool can be used to filter web requests associated with the SQL Injection attack?
SQL injectionweb request filteringUrlScanweb application security - Question #190Security Incident Response
Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for further investigation and confirmation. Charline, after a thorough investigati...
SOC workflowincident escalationIRT ticketingL2 analyst - Question #191Threat Intelligence
Which of the following threat intelligence helps cyber security professionals such as security operations managers, network operations center and incident responders to understand...
operational threat intelligencethreat intelligence typesadversary TTPsattack vectors - Question #192Security Incident Detection
If the SIEM generates the following four alerts at the same time: I . Firewall blocking traffic from getting into the network alerts II . SQL injection attempt alerts III . Data de...
alert triagealert prioritizationSIEM alertsfirewall alerts - Question #193SOC Fundamentals and Operations
InfoSystem LLC, a US-based company, is establishing an in-house SOC. John has been given the responsibility to finalize strategy, policies, and procedures for the SOC. Identify the...
CISOSOC rolessecurity governanceSOC strategy - Question #194Security Incident Detection
Which of the following service provides phishing protection and content filtering to manage the Internet experience on and off your network with the acceptable use or compliance po...
OpenDNSphishing protectioncontent filteringDNS security - Question #195Security Incident Detection
David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not able to find any suspicious events. This type of incident is categorized int...
false negativeincident classificationdetection failurealert analysis - Question #196Security Incident Response
Emmanuel is working as a SOC analyst in a company named Tobey Tech. The manager of Tobey Tech recently recruited an Incident Response Team (IRT) for his company. In the process of...
IRT workflowincident analysisincident validationincident response process - Question #197SOC Fundamentals and Operations
Identify the HTTP status codes that represents the server error.
HTTP status codes5XX server errorsweb server monitoringlog analysis - Question #198Security Incident Detection
Jony, a security analyst, while monitoring IIS logs, identified events shown in the figure below. What does this event log indicate?
SQL injectionIIS log analysisattack identificationweb attack indicators - Question #199Security Incident Detection
Which attack works like a dictionary attack, but adds some numbers and symbols to the words from the dictionary and tries to crack the password?
hybrid attackpassword crackingdictionary attackcredential attacks - Question #200Security Incident Response
Which of the following attack can be eradicated by converting all non-alphanumeric characters to HTML character entities before displaying the user input in search engines and foru...
XSS attackHTML encodinginput sanitizationweb attack mitigation