EC-COUNCIL 312-39 Cert Guide PDF 100% Cover Real Exam Questions [Q42-Q59]

Share

EC-COUNCIL 312-39 Cert Guide PDF 100% Cover Real Exam Questions

Pass 312-39 Exam - Real Questions and Answers

NEW QUESTION # 42
Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for further investigation and confirmation. Charline, after a thorough investigation, confirmed the incident and assigned it with an initial priority.
What would be her next action according to the SOC workflow?

  • A. She should communicate this incident to the media immediately
  • B. She should immediately escalate this issue to the management
  • C. She should immediately contact the network administrator to solve the problem
  • D. She should formally raise a ticket and forward it to the IRT

Answer: D

Explanation:


NEW QUESTION # 43
Jony, a security analyst, while monitoring IIS logs, identified events shown in the figure below.

What does this event log indicate?

  • A. XSS Attack
  • B. SQL Injection Attack
  • C. Directory Traversal Attack
  • D. Parameter Tampering Attack

Answer: D


NEW QUESTION # 44
The Syslog message severity levels are labelled from level 0 to level 7.
What does level 0 indicate?

  • A. Notification
  • B. Emergency
  • C. Debugging
  • D. Alert

Answer: A


NEW QUESTION # 45
Identify the event severity level in Windows logs for the events that are not necessarily significant, but may indicate a possible future problem.

  • A. Information
  • B. Error
  • C. Failure Audit
  • D. Warning

Answer: D


NEW QUESTION # 46
Which of the following tool can be used to filter web requests associated with the SQL Injection attack?

  • A. UrlScan
  • B. Hydra
  • C. ZAP proxy
  • D. Nmap

Answer: A


NEW QUESTION # 47
Which of the following attack can be eradicated by filtering improper XML syntax?

  • A. Insufficient Logging and Monitoring Attacks
  • B. Web Services Attacks
  • C. CAPTCHA Attacks
  • D. SQL Injection Attacks

Answer: D


NEW QUESTION # 48
Which of the following contains the performance measures, and proper project and time management details?

  • A. Incident Response Tactics
  • B. Incident Response Procedures
  • C. Incident Response Policy
  • D. Incident Response Process

Answer: C

Explanation:


NEW QUESTION # 49
Emmanuel is working as a SOC analyst in a company named Tobey Tech. The manager of Tobey Tech recently recruited an Incident Response Team (IRT) for his company. In the process of collaboration with the IRT, Emmanuel just escalated an incident to the IRT.
What is the first step that the IRT will do to the incident escalated by Emmanuel?

  • A. Incident Prioritization
  • B. Incident Analysis and Validation
  • C. Incident Classification
  • D. Incident Recording

Answer: C

Explanation:
Explanation
Graphical user interface Description automatically generated


NEW QUESTION # 50
An organization is implementing and deploying the SIEM with following capabilities.

What kind of SIEM deployment architecture the organization is planning to implement?

  • A. Self-hosted, MSSP Managed
  • B. Cloud, MSSP Managed
  • C. Self-hosted, Self-Managed
  • D. Self-hosted, Jointly Managed

Answer: B


NEW QUESTION # 51
Identify the attack in which the attacker exploits a target system through publicly known but still unpatched vulnerabilities.

  • A. Slow DoS Attack
  • B. DNS Poisoning Attack
  • C. DHCP Starvation
  • D. Zero-Day Attack

Answer: D


NEW QUESTION # 52
Which of the following are the responsibilities of SIEM Agents?
1.Collecting data received from various devices sending data to SIEM before forwarding it to the central engine.
2.Normalizing data received from various devices sending data to SIEM before forwarding it to the central engine.
3.Co-relating data received from various devices sending data to SIEM before forwarding it to the central engine.
4.Visualizing data received from various devices sending data to SIEM before forwarding it to the central engine.

  • A. 1 and 2
  • B. 3 and 1
  • C. 1 and 4
  • D. 2 and 3

Answer: A

Explanation:


NEW QUESTION # 53
Bonney's system has been compromised by a gruesome malware.
What is the primary step that is advisable to Bonney in order to contain the malware incident from spreading?

  • A. Leave it to the network administrators to handle
  • B. Turn off the infected machine
  • C. Complaint to police in a formal way regarding the incident
  • D. Call the legal department in the organization and inform about the incident

Answer: B


NEW QUESTION # 54
Which one of the following is the correct flow for Setting Up a Computer Forensics Lab?

  • A. Planning and budgeting -> Physical location and structural design considerations -> Forensics lab licensing ->Work area considerations -> Human resource considerations -> Physical security recommendations
  • B. Planning and budgeting -> Forensics lab licensing -> Physical location and structural design considerations -> Work area considerations -> Physical security recommendations -> Human resource considerations
  • C. Planning and budgeting -> Physical location and structural design considerations-> Forensics lab licensing -> Human resource considerations -> Work area considerations -> Physical security recommendations
  • D. Planning and budgeting -> Physical location and structural design considerations -> Work area considerations -> Human resource considerations -> Physical security recommendations -> Forensics lab licensing

Answer: D


NEW QUESTION # 55
Identify the password cracking attempt involving a precomputed dictionary of plaintext passwords and their corresponding hash values to crack the password.

  • A. Syllable Attack
  • B. Bruteforce Attack
  • C. Dictionary Attack
  • D. Rainbow Table Attack

Answer: C


NEW QUESTION # 56
The threat intelligence, which will help you, understand adversary intent and make informed decision to ensure appropriate security in alignment with risk.
What kind of threat intelligence described above?

  • A. Strategic Threat Intelligence
  • B. Functional Threat Intelligence
  • C. Operational Threat Intelligence
  • D. Tactical Threat Intelligence

Answer: A


NEW QUESTION # 57
Which of the following tool is used to recover from web application incident?

  • A. Symantec Secure Web Gateway
  • B. Proxy Workbench
  • C. CrowdStrike FalconTM Orchestrator
  • D. Smoothwall SWG

Answer: A


NEW QUESTION # 58
Which of the following tool is used to recover from web application incident?

  • A. Proxy Workbench
  • B. Symantec Secure Web Gateway
  • C. CrowdStrike FalconTM Orchestrator
  • D. Smoothwall SWG

Answer: C

Explanation:


NEW QUESTION # 59
......


EC-COUNCIL 312-39 (Certified SOC Analyst (CSA)) certification exam is designed to test the knowledge and skills of candidates in the field of security operations center (SOC) analysis. Certified SOC Analyst (CSA) certification is recognized globally and is highly valued by employers in the cybersecurity industry. 312-39 exam is designed to test the candidate's ability to handle security incidents, detect and respond to security threats, and manage the security infrastructure of an organization.

 

100% Free 312-39 Daily Practice Exam With 102 Questions: https://www.prepawaypdf.com/EC-COUNCIL/312-39-practice-exam-dumps.html

Pass 312-39 Review Guide, Reliable 312-39 Test Engine: https://drive.google.com/open?id=1uT45je7KOVDm__ONvMrhT3_PJszx-KGr