Download 312-39 Exam Dumps Questions to get 100% Success in EC-COUNCIL [Q22-Q47]

Share

Download 312-39 Exam Dumps Questions to get 100% Success in EC-COUNCIL 

100% Accurate Answers! 312-39 Actual Real Exam Questions

NEW QUESTION # 22
Which of the log storage method arranges event logs in the form of a circular buffer?

  • A. wrapping
  • B. non-wrapping
  • C. LIFO
  • D. FIFO

Answer: A

Explanation:


NEW QUESTION # 23
In which of the following incident handling and response stages, the root cause of the incident must be found from the forensic results?

  • A. Systems Recovery
  • B. Evidence Gathering
  • C. Evidence Handling
  • D. Eradication

Answer: B


NEW QUESTION # 24
Which of the following tool is used to recover from web application incident?

  • A. Smoothwall SWG
  • B. Symantec Secure Web Gateway
  • C. Proxy Workbench
  • D. CrowdStrike FalconTM Orchestrator

Answer: B


NEW QUESTION # 25
Which of the following can help you eliminate the burden of investigating false positives?

  • A. Treating every alert as high level
  • B. Not trusting the security devices
  • C. Keeping default rules
  • D. Ingesting the context data

Answer: D

Explanation:


NEW QUESTION # 26
John, a SOC analyst, while monitoring and analyzing Apache web server logs, identified an event log matching Regex /(\.|(%|%25)2E)(\.|(%|%25)2E)(\/|(%|%25)2F|\\|(%|%25)5C)/i.
What does this event log indicate?

  • A. Parameter Tampering Attack
  • B. Directory Traversal Attack
  • C. XSS Attack
  • D. SQL injection Attack

Answer: B

Explanation:


NEW QUESTION # 27
Which of the following factors determine the choice of SIEM architecture?

  • A. Network Topology
  • B. SMTP Configuration
  • C. DNS Configuration
  • D. DHCP Configuration

Answer: A

Explanation:


NEW QUESTION # 28
Which of the following Windows event is logged every time when a user tries to access the "Registry" key?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D


NEW QUESTION # 29
Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry:
May 06 2018 21:27:27 asa 1: %ASA -5 - 11008: User 'enable_15' executed the 'configure term' command What does the security level in the above log indicates?

  • A. Normal but significant message
  • B. Informational message
  • C. Warning condition message
  • D. Critical condition message

Answer: C


NEW QUESTION # 30
Harley is working as a SOC analyst with Powell Tech. Powell Inc. is using Internet Information Service (IIS) version 7.0 to host their website.
Where will Harley find the web server logs, if he wants to investigate them for any anomalies?

  • A. SystemDrive%\ inetpub\LogFiles\logs\W3SVCN
  • B. SystemDrive%\LogFiles\inetpub\logs\W3SVCN
  • C. SystemDrive%\inetpub\logs\LogFiles\W3SVCN
  • D. %SystemDrive%\LogFiles\logs\W3SVCN

Answer: C

Explanation:


NEW QUESTION # 31
Which of the following data source will a SOC Analyst use to monitor connections to the insecure ports?

  • A. DNS Data
  • B. IIS Data
  • C. DHCP Data
  • D. Netstat Data

Answer: D


NEW QUESTION # 32
Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for further investigation and confirmation. Charline, after a thorough investigation, confirmed the incident and assigned it with an initial priority.
What would be her next action according to the SOC workflow?

  • A. She should immediately escalate this issue to the management
  • B. She should formally raise a ticket and forward it to the IRT
  • C. She should immediately contact the network administrator to solve the problem
  • D. She should communicate this incident to the media immediately

Answer: B

Explanation:


NEW QUESTION # 33
Which of the following attack can be eradicated by disabling of "allow_url_fopen and allow_url_include" in the php.ini file?

  • A. LDAP Injection Attacks
  • B. URL Injection Attacks
  • C. Command Injection Attacks
  • D. File Injection Attacks

Answer: D

Explanation:


NEW QUESTION # 34
Robin, a SOC engineer in a multinational company, is planning to implement a SIEM. He realized that his organization is capable of performing only Correlation, Analytics, Reporting, Retention, Alerting, and Visualization required for the SIEM implementation and has to take collection and aggregation services from a Managed Security Services Provider (MSSP).
What kind of SIEM is Robin planning to implement?

  • A. Cloud, Self-Managed
  • B. Self-hosted, MSSP Managed
  • C. Hybrid Model, Jointly Managed
  • D. Self-hosted, Self-Managed

Answer: B


NEW QUESTION # 35
Which of the following tool can be used to filter web requests associated with the SQL Injection attack?

  • A. ZAP proxy
  • B. Nmap
  • C. Hydra
  • D. UrlScan

Answer: D


NEW QUESTION # 36
An attacker exploits the logic validation mechanisms of an e-commerce website. He successfully purchases a product worth $100 for $10 by modifying the URL exchanged between the client and the server.
Original
URL: http://www.buyonline.com/product.aspx?profile=12
&debit=100
Modified URL: http://www.buyonline.com/product.aspx?profile=12
&debit=10
Identify the attack depicted in the above scenario.

  • A. Parameter Tampering Attack
  • B. SQL Injection Attack
  • C. Session Fixation Attack
  • D. Denial-of-Service Attack

Answer: C


NEW QUESTION # 37
What type of event is recorded when an application driver loads successfully in Windows?

  • A. Error
  • B. Information
  • C. Warning
  • D. Success Audit

Answer: B


NEW QUESTION # 38
Harley is working as a SOC analyst with Powell Tech. Powell Inc. is using Internet Information Service (IIS) version 7.0 to host their website.
Where will Harley find the web server logs, if he wants to investigate them for any anomalies?

  • A. SystemDrive%\ inetpub\LogFiles\logs\W3SVCN
  • B. SystemDrive%\LogFiles\inetpub\logs\W3SVCN
  • C. SystemDrive%\inetpub\logs\LogFiles\W3SVCN
  • D. %SystemDrive%\LogFiles\logs\W3SVCN

Answer: B


NEW QUESTION # 39
Emmanuel is working as a SOC analyst in a company named Tobey Tech. The manager of Tobey Tech recently recruited an Incident Response Team (IRT) for his company. In the process of collaboration with the IRT, Emmanuel just escalated an incident to the IRT.
What is the first step that the IRT will do to the incident escalated by Emmanuel?

  • A. Incident Classification
  • B. Incident Recording
  • C. Incident Analysis and Validation
  • D. Incident Prioritization

Answer: A

Explanation:
Explanation
Graphical user interface Description automatically generated


NEW QUESTION # 40
Which of the following fields in Windows logs defines the type of event occurred, such as Correlation Hint, Response Time, SQM, WDI Context, and so on?

  • A. Keywords
  • B. Task Category
  • C. Level
  • D. Source

Answer: A


NEW QUESTION # 41
In which log collection mechanism, the system or application sends log records either on the local disk or over the network.

  • A. rule-based
  • B. signature-based
  • C. pull-based
  • D. push-based

Answer: D

Explanation:


NEW QUESTION # 42
Shawn is a security manager working at Lee Inc Solution. His organization wants to develop threat intelligent strategy plan. As a part of threat intelligent strategy plan, he suggested various components, such as threat intelligence requirement analysis, intelligence and collection planning, asset identification, threat reports, and intelligence buy-in.
Which one of the following components he should include in the above threat intelligent strategy plan to make it effective?

  • A. Threat trending
  • B. Threat boosting
  • C. Threat buy-in
  • D. Threat pivoting

Answer: A

Explanation:


NEW QUESTION # 43
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.
Which of the following data source will he use to prepare the dashboard?

  • A. DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.
  • B. IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.
  • C. DNS/ Web Server logs with IP addresses.
  • D. Apache/ Web Server logs with IP addresses and Host Name.

Answer: A

Explanation:


NEW QUESTION # 44
David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not able to find any suspicious events.
This type of incident is categorized into?

  • A. False Negative Incidents
  • B. True Negative Incidents
  • C. False positive Incidents
  • D. True Positive Incidents

Answer: A

Explanation:


NEW QUESTION # 45
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.
Which of the following data source will he use to prepare the dashboard?

  • A. IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.
  • B. Apache/ Web Server logs with IP addresses and Host Name.
  • C. DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.
  • D. DNS/ Web Server logs with IP addresses.

Answer: B


NEW QUESTION # 46
What does HTTPS Status code 403 represents?

  • A. Internal Server Error
  • B. Forbidden Error
  • C. Unauthorized Error
  • D. Not Found Error

Answer: B


NEW QUESTION # 47
......


The Certified SOC Analyst (CSA) Exam is a certification exam offered by the EC-COUNCIL. 312-39 exam focuses on assessing the skills and knowledge of candidates in detecting, analyzing and responding to cybersecurity threats in a Security Operations Center (SOC) environment. The purpose of 312-39 exam is to validate the qualifications of candidates in providing a strong response to cybersecurity incidents and developing a secure SOC.

 

Best Value Available! Realistic Verified Free 312-39 Exam Questions: https://certmagic.surepassexams.com/312-39-exam-bootcamp.html