Updated Jan-2023 Exam Engine for 312-39 Exam Free Demo & 365 Day Updates [Q10-Q28]

Share

Updated Jan-2023 Exam Engine for 312-39 Exam Free Demo & 365 Day Updates

Exam Passing Guarantee 312-39 Exam with Accurate Quastions!

NEW QUESTION 10
Which of the following data source can be used to detect the traffic associated with Bad Bot User-Agents?

  • A. Windows Event Log
  • B. Router Logs
  • C. Switch Logs
  • D. Web Server Logs

Answer: D

 

NEW QUESTION 11
An organization is implementing and deploying the SIEM with following capabilities.

What kind of SIEM deployment architecture the organization is planning to implement?

  • A. Self-hosted, MSSP Managed
  • B. Self-hosted, Self-Managed
  • C. Self-hosted, Jointly Managed
  • D. Cloud, MSSP Managed

Answer: D

 

NEW QUESTION 12
Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for further investigation and confirmation. Charline, after a thorough investigation, confirmed the incident and assigned it with an initial priority.
What would be her next action according to the SOC workflow?

  • A. She should communicate this incident to the media immediately
  • B. She should immediately contact the network administrator to solve the problem
  • C. She should formally raise a ticket and forward it to the IRT
  • D. She should immediately escalate this issue to the management

Answer: B

 

NEW QUESTION 13
Ray is a SOC analyst in a company named Queens Tech. One Day, Queens Tech is affected by a DoS/DDoS attack. For the containment of this incident, Ray and his team are trying to provide additional bandwidth to the network devices and increasing the capacity of the servers.
What is Ray and his team doing?

  • A. Absorbing the Attack
  • B. Diverting the Traffic
  • C. Blocking the Attacks
  • D. Degrading the services

Answer: A

 

NEW QUESTION 14
Emmanuel is working as a SOC analyst in a company named Tobey Tech. The manager of Tobey Tech recently recruited an Incident Response Team (IRT) for his company. In the process of collaboration with the IRT, Emmanuel just escalated an incident to the IRT.
What is the first step that the IRT will do to the incident escalated by Emmanuel?

  • A. Incident Classification
  • B. Incident Analysis and Validation
  • C. Incident Recording
  • D. Incident Prioritization

Answer: A

Explanation:
Explanation
Graphical user interface Description automatically generated

 

NEW QUESTION 15
If the SIEM generates the following four alerts at the same time:
I.Firewall blocking traffic from getting into the network alerts
II.SQL injection attempt alerts
III.Data deletion attempt alerts
IV.Brute-force attempt alerts
Which alert should be given least priority as per effective alert triaging?

  • A. IV
  • B. II
  • C. III
  • D. I

Answer: D

 

NEW QUESTION 16
Shawn is a security manager working at Lee Inc Solution. His organization wants to develop threat intelligent strategy plan. As a part of threat intelligent strategy plan, he suggested various components, such as threat intelligence requirement analysis, intelligence and collection planning, asset identification, threat reports, and intelligence buy-in.
Which one of the following components he should include in the above threat intelligent strategy plan to make it effective?

  • A. Threat pivoting
  • B. Threat buy-in
  • C. Threat boosting
  • D. Threat trending

Answer: B

 

NEW QUESTION 17
What does HTTPS Status code 403 represents?

  • A. Internal Server Error
  • B. Forbidden Error
  • C. Unauthorized Error
  • D. Not Found Error

Answer: B

 

NEW QUESTION 18
Robin, a SOC engineer in a multinational company, is planning to implement a SIEM. He realized that his organization is capable of performing only Correlation, Analytics, Reporting, Retention, Alerting, and Visualization required for the SIEM implementation and has to take collection and aggregation services from a Managed Security Services Provider (MSSP).
What kind of SIEM is Robin planning to implement?

  • A. Self-hosted, MSSP Managed
  • B. Cloud, Self-Managed
  • C. Self-hosted, Self-Managed
  • D. Hybrid Model, Jointly Managed

Answer: B

Explanation:

 

NEW QUESTION 19
John, a SOC analyst, while monitoring and analyzing Apache web server logs, identified an event log matching Regex /(\.|(%|%25)2E)(\.|(%|%25)2E)(\/|(%|%25)2F|\\|(%|%25)5C)/i.
What does this event log indicate?

  • A. SQL injection Attack
  • B. Directory Traversal Attack
  • C. Parameter Tampering Attack
  • D. XSS Attack

Answer: D

 

NEW QUESTION 20
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.
Which of the following data source will he use to prepare the dashboard?

  • A. Apache/ Web Server logs with IP addresses and Host Name.
  • B. DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.
  • C. DNS/ Web Server logs with IP addresses.
  • D. IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.

Answer: A

 

NEW QUESTION 21
Identify the HTTP status codes that represents the server error.

  • A. 2XX
  • B. 4XX
  • C. 1XX
  • D. 5XX

Answer: D

 

NEW QUESTION 22
Which of the following formula represents the risk?

  • A. Risk = Likelihood * Severity * Asset Value
  • B. Risk = Likelihood * Consequence * Severity
  • C. Risk = Likelihood * Impact * Severity
  • D. Risk = Likelihood * Impact * Asset Value

Answer: B

 

NEW QUESTION 23
Which of the following event detection techniques uses User and Entity Behavior Analytics (UEBA)?

  • A. Heuristic-based detection
  • B. Signature-based detection
  • C. Rule-based detection
  • D. Anomaly-based detection

Answer: D

 

NEW QUESTION 24
Rinni, SOC analyst, while monitoring IDS logs detected events shown in the figure below.

What does this event log indicate?

  • A. SQL Injection Attack
  • B. XSS Attack
  • C. Directory Traversal Attack
  • D. Parameter Tampering Attack

Answer: D

 

NEW QUESTION 25
Which of the following command is used to view iptables logs on Ubuntu and Debian distributions?

  • A. # tailf /var/log/messages
  • B. $ tailf /var/log/kern.log
  • C. $ tailf /var/log/sys/kern.log
  • D. # tailf /var/log/sys/messages

Answer: B

 

NEW QUESTION 26
Jony, a security analyst, while monitoring IIS logs, identified events shown in the figure below.

What does this event log indicate?

  • A. SQL Injection Attack
  • B. XSS Attack
  • C. Directory Traversal Attack
  • D. Parameter Tampering Attack

Answer: A

Explanation:

 

NEW QUESTION 27
Identify the type of attack, an attacker is attempting on www.example.com website.

  • A. SQL Injection Attack
  • B. Denial-of-Service Attack
  • C. Session Attack
  • D. Cross-site Scripting Attack

Answer: D

 

NEW QUESTION 28
......

Exam Questions for 312-39 Updated Versions With Test Engine: https://certmagic.surepassexams.com/312-39-exam-bootcamp.html