[Dec-2021] Updated EC-COUNCIL 312-39 Dumps – PDF & Online Engine
312-39.pdf - Questions Answers PDF Sample Questions Reliable
The EC-Council 312-39 exam is designed to evaluate and validate the extensive knowledge and skills of the candidates in the job tasks associated with the SOC Analyst role. This test is the first step towards becoming an active player in the security operations center. The potential individuals for the exam demonstrate the in-demand and trending technical skills in carrying out the entry-level and mid-level operations. The students will be measured based on their expertise in log correlation and management, advanced incident detection, SIEM deployment, incident detection, incident response, and management of different SOC processes.
What Does It Cover?
The EC-Council 312-39 exam is built around the topic areas listed below:
- Security Operations & Management;
- Incidents, Events, and Logging;
- Incident Detection with Security Information and Event Management (SIEM);
- Incident Response.
- Understanding Cyber Threats, IoCs, and Attack Methodology;
- Enhanced Incident Detection with Threat Intelligence;
Can You Study with Online Courses?
Yes! This is one of the best learning approaches you can adopt to crack 312-39 exam easily. And the next section covers one such study material:
- Certified SOC Analyst (CSA)
The Certified SOC Analyst (CSA) course is an intense learning program that runs for 3 days. It is a credentialing study option that equips candidates with in-demand technical skills and knowledge relating to the management of a Security Operations Center (SOC). This learning path, in particular, focuses on helping candidates master what they should know to successfully perform the fundamental SOC operations under the recognized concepts of SIEM deployment, incident response, log management along with correlation, and advanced incident detection among other skills. All in all, this course will help you understand how to perform different SOC processes and work together with CSIRT if necessary to ensure your company achieves its goals. You may want to check out the official learning page to find out more information about this course and other learning options.
NEW QUESTION 24
Which of the following tool is used to recover from web application incident?
- A. CrowdStrike FalconTM Orchestrator
- B. Symantec Secure Web Gateway
- C. Smoothwall SWG
- D. Proxy Workbench
Answer: B
NEW QUESTION 25
Identify the event severity level in Windows logs for the events that are not necessarily significant, but may indicate a possible future problem.
- A. Failure Audit
- B. Warning
- C. Error
- D. Information
Answer: B
NEW QUESTION 26
If the SIEM generates the following four alerts at the same time:
I.Firewall blocking traffic from getting into the network alerts
II.SQL injection attempt alerts
III.Data deletion attempt alerts
IV.Brute-force attempt alerts
Which alert should be given least priority as per effective alert triaging?
- A. II
- B. I
- C. IV
- D. III
Answer: B
NEW QUESTION 27
Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry:
May 06 2018 21:27:27 asa 1: %ASA -5 - 11008: User 'enable_15' executed the 'configure term' command What does the security level in the above log indicates?
- A. Critical condition message
- B. Warning condition message
- C. Normal but significant message
- D. Informational message
Answer: B
NEW QUESTION 28
Which of the following fields in Windows logs defines the type of event occurred, such as Correlation Hint, Response Time, SQM, WDI Context, and so on?
- A. Source
- B. Task Category
- C. Keywords
- D. Level
Answer: C
NEW QUESTION 29
InfoSystem LLC, a US-based company, is establishing an in-house SOC. John has been given the responsibility to finalize strategy, policies, and procedures for the SOC.
Identify the job role of John.
- A. Security Engineer
- B. Chief Information Security Officer (CISO)
- C. Security Analyst - L2
- D. Security Analyst - L1
Answer: B
NEW QUESTION 30
Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for further investigation and confirmation. Charline, after a thorough investigation, confirmed the incident and assigned it with an initial priority.
What would be her next action according to the SOC workflow?
- A. She should communicate this incident to the media immediately
- B. She should immediately contact the network administrator to solve the problem
- C. She should formally raise a ticket and forward it to the IRT
- D. She should immediately escalate this issue to the management
Answer: B
NEW QUESTION 31
An organization is implementing and deploying the SIEM with following capabilities.
What kind of SIEM deployment architecture the organization is planning to implement?
- A. Self-hosted, Self-Managed
- B. Cloud, MSSP Managed
- C. Self-hosted, Jointly Managed
- D. Self-hosted, MSSP Managed
Answer: B
NEW QUESTION 32
Sam, a security analyst with INFOSOL INC., while monitoring and analyzing IIS logs, detected an event matching regex /\\w*((\%27)|(\'))((\%6F)|o|(\%4F))((\%72)|r|(\%52))/ix.
What does this event log indicate?
- A. SQL Injection Attack
- B. Parameter Tampering Attack
- C. XSS Attack
- D. Directory Traversal Attack
Answer: A
NEW QUESTION 33
Which of the following attack can be eradicated by filtering improper XML syntax?
- A. Insufficient Logging and Monitoring Attacks
- B. Web Services Attacks
- C. SQL Injection Attacks
- D. CAPTCHA Attacks
Answer: C
NEW QUESTION 34
According to the Risk Matrix table, what will be the risk level when the probability of an attack is very high, and the impact of that attack is major?
NOTE: It is mandatory to answer the question before proceeding to the next one.
- A. High
- B. Low
- C. Extreme
- D. Medium
Answer: A
NEW QUESTION 35
Which of the following attacks causes sudden changes in file extensions or increase in file renames at rapid speed?
- A. DoS Attack
- B. Ransomware Attack
- C. File Injection Attack
- D. DHCP starvation Attack
Answer: B
NEW QUESTION 36
Jony, a security analyst, while monitoring IIS logs, identified events shown in the figure below.
What does this event log indicate?
- A. XSS Attack
- B. Parameter Tampering Attack
- C. SQL Injection Attack
- D. Directory Traversal Attack
Answer: B
NEW QUESTION 37
Which of the following Windows event is logged every time when a user tries to access the "Registry" key?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION 38
Identify the attack in which the attacker exploits a target system through publicly known but still unpatched vulnerabilities.
- A. Slow DoS Attack
- B. DNS Poisoning Attack
- C. Zero-Day Attack
- D. DHCP Starvation
Answer: C
NEW QUESTION 39
Identify the attack when an attacker by several trial and error can read the contents of a password file present in the restricted etc folder just by manipulating the URL in the browser as shown:
http://www.terabytes.com/process.php./../../../../etc/passwd
- A. SQL Injection Attack
- B. Directory Traversal Attack
- C. Form Tampering Attack
- D. Denial-of-Service Attack
Answer: A
NEW QUESTION 40
In which log collection mechanism, the system or application sends log records either on the local disk or over the network.
- A. signature-based
- B. push-based
- C. rule-based
- D. pull-based
Answer: C
NEW QUESTION 41
Rinni, SOC analyst, while monitoring IDS logs detected events shown in the figure below.
What does this event log indicate?
- A. XSS Attack
- B. Parameter Tampering Attack
- C. SQL Injection Attack
- D. Directory Traversal Attack
Answer: B
NEW QUESTION 42
A type of threat intelligent that find out the information about the attacker by misleading them is known as
.
- A. Counter Intelligence
- B. Operational Intelligence
- C. Threat trending Intelligence
- D. Detection Threat Intelligence
Answer: B
NEW QUESTION 43
An attacker, in an attempt to exploit the vulnerability in the dynamically generated welcome page, inserted code at the end of the company's URL as follows:
http://technosoft.com.com/<script>alert("WARNING: The application has encountered an error");</script>.
Identify the attack demonstrated in the above scenario.
- A. Cross-site Scripting Attack
- B. Session Attack
- C. SQL Injection Attack
- D. Denial-of-Service Attack
Answer: B
NEW QUESTION 44
Which of the following attack inundates DHCP servers with fake DHCP requests to exhaust all available IP addresses?
- A. DHCP Cache Poisoning
- B. DHCP Spoofing Attack
- C. DHCP Starvation Attacks
- D. DHCP Port Stealing
Answer: C
NEW QUESTION 45
Shawn is a security manager working at Lee Inc Solution. His organization wants to develop threat intelligent strategy plan. As a part of threat intelligent strategy plan, he suggested various components, such as threat intelligence requirement analysis, intelligence and collection planning, asset identification, threat reports, and intelligence buy-in.
Which one of the following components he should include in the above threat intelligent strategy plan to make it effective?
- A. Threat buy-in
- B. Threat boosting
- C. Threat pivoting
- D. Threat trending
Answer: A
NEW QUESTION 46
Ray is a SOC analyst in a company named Queens Tech. One Day, Queens Tech is affected by a DoS/DDoS attack. For the containment of this incident, Ray and his team are trying to provide additional bandwidth to the network devices and increasing the capacity of the servers.
What is Ray and his team doing?
- A. Degrading the services
- B. Diverting the Traffic
- C. Blocking the Attacks
- D. Absorbing the Attack
Answer: D
NEW QUESTION 47
......
EC-COUNCIL 312-39 Dumps PDF Are going to be The Best Score: https://www.crampdf.com/312-39-exam-prep-dumps.html
EC-COUNCIL CSA 312-39 Exam and Certification Test Engine: https://drive.google.com/open?id=17yQqNFykFmqEWLoXTf5Z7uz7yJB6_PZI