
[Sep-2021] Pass 312-39 Exam in First Attempt Updated312-39 SureTorrent Exam Question
EC-COUNCIL CSA Dumps 312-39 Exam for Full Questions - Exam Study Guide
NEW QUESTION 53
John, SOC analyst wants to monitor the attempt of process creation activities from any of their Windows endpoints.
Which of following Splunk query will help him to fetch related logs associated with process creation?
- A. index=windows LogName=Security EventCode=5688 NOT (Account_Name=*$) ... ... ...
- B. index=windows LogName=Security EventCode=3688 NOT (Account_Name=*$) .. .. ..
- C. index=windows LogName=Security EventCode=4688 NOT (Account_Name=*$) .. .. ..
- D. index=windows LogName=Security EventCode=4678 NOT (Account_Name=*$) .. .. ... ..
Answer: C
NEW QUESTION 54
Properly applied cyber threat intelligence to the SOC team help them in discovering TTPs.
What does these TTPs refer to?
- A. Targets, Threats, and Process
- B. Tactics, Targets, and Process
- C. Tactics, Threats, and Procedures
- D. Tactics, Techniques, and Procedures
Answer: D
NEW QUESTION 55
Which of the following attack can be eradicated by converting all non-alphanumeric characters to HTML character entities before displaying the user input in search engines and forums?
- A. Broken Access Control Attacks
- B. Session Management Attacks
- C. Web Services Attacks
- D. XSS Attacks
Answer: D
NEW QUESTION 56
Which of the following command is used to view iptables logs on Ubuntu and Debian distributions?
- A. $ tailf /var/log/kern.log
- B. # tailf /var/log/sys/messages
- C. $ tailf /var/log/sys/kern.log
- D. # tailf /var/log/messages
Answer: A
NEW QUESTION 57
What type of event is recorded when an application driver loads successfully in Windows?
- A. Warning
- B. Error
- C. Success Audit
- D. Information
Answer: D
NEW QUESTION 58
Which of the following attacks causes sudden changes in file extensions or increase in file renames at rapid speed?
- A. Ransomware Attack
- B. DoS Attack
- C. File Injection Attack
- D. DHCP starvation Attack
Answer: A
NEW QUESTION 59
Sam, a security analyst with INFOSOL INC., while monitoring and analyzing IIS logs, detected an event matching regex /\\w*((\%27)|(\'))((\%6F)|o|(\%4F))((\%72)|r|(\%52))/ix.
What does this event log indicate?
- A. XSS Attack
- B. SQL Injection Attack
- C. Parameter Tampering Attack
- D. Directory Traversal Attack
Answer: B
NEW QUESTION 60
Which of the following Windows event is logged every time when a user tries to access the "Registry" key?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION 61
Which of the following data source will a SOC Analyst use to monitor connections to the insecure ports?
- A. DHCP Data
- B. DNS Data
- C. IIS Data
- D. Netstat Data
Answer: D
NEW QUESTION 62
Which of the following event detection techniques uses User and Entity Behavior Analytics (UEBA)?
- A. Signature-based detection
- B. Anomaly-based detection
- C. Rule-based detection
- D. Heuristic-based detection
Answer: B
NEW QUESTION 63
Which of the following is a report writing tool that will help incident handlers to generate efficient reports on detected incidents during incident response process?
- A. threat_note
- B. MagicTree
- C. IntelMQ
- D. Malstrom
Answer: C
NEW QUESTION 64
Ray is a SOC analyst in a company named Queens Tech. One Day, Queens Tech is affected by a DoS/DDoS attack. For the containment of this incident, Ray and his team are trying to provide additional bandwidth to the network devices and increasing the capacity of the servers.
What is Ray and his team doing?
- A. Degrading the services
- B. Blocking the Attacks
- C. Diverting the Traffic
- D. Absorbing the Attack
Answer: D
NEW QUESTION 65
Which of the following Windows features is used to enable Security Auditing in Windows?
- A. Windows Defender
- B. Windows Firewall
- C. Local Group Policy Editor
- D. Bitlocker
Answer: C
NEW QUESTION 66
John, a threat analyst at GreenTech Solutions, wants to gather information about specific threats against the organization. He started collecting information from various sources, such as humans, social media, chat room, and so on, and created a report that contains malicious activity.
Which of the following types of threat intelligence did he use?
- A. Strategic Threat Intelligence
- B. Technical Threat Intelligence
- C. Tactical Threat Intelligence
- D. Operational Threat Intelligence
Answer: D
NEW QUESTION 67
Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for further investigation and confirmation. Charline, after a thorough investigation, confirmed the incident and assigned it with an initial priority.
What would be her next action according to the SOC workflow?
- A. She should immediately contact the network administrator to solve the problem
- B. She should communicate this incident to the media immediately
- C. She should formally raise a ticket and forward it to the IRT
- D. She should immediately escalate this issue to the management
Answer: A
NEW QUESTION 68
David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not able to find any suspicious events.
This type of incident is categorized into?
- A. False Negative Incidents
- B. True Positive Incidents
- C. False positive Incidents
- D. True Negative Incidents
Answer: D
NEW QUESTION 69
......
Authentic Best resources for 312-39 Online Practice Exam: https://www.suretorrent.com/312-39-exam-guide-torrent.html
Get the superior quality 312-39 Dumps with explanations waiting just for you, get it now: https://drive.google.com/open?id=19lm9nOlqJrY4QZn3HM3FMHB9CzMjfbEK