May-2023 EC-COUNCIL 312-39 Actual Questions and 100% Cover Real Exam Questions 312-39 Free Exam Questions and Answers PDF Updated on May-2023 EC-COUNCIL 312-39 (Certified SOC Analyst (CSA)) Certification Exam is designed for professionals who want to validate their expertise in performing SOC (Security Operations Center) analysis, incident response, and threat hunting. This certification exam is ideal [...]

May-2023 EC-COUNCIL 312-39 Actual Questions and 100% Cover Real Exam Questions [Q25-Q43]

Share

May-2023 EC-COUNCIL 312-39 Actual Questions and 100% Cover Real Exam Questions

312-39 Free Exam Questions and Answers PDF Updated on May-2023


EC-COUNCIL 312-39 (Certified SOC Analyst (CSA)) Certification Exam is designed for professionals who want to validate their expertise in performing SOC (Security Operations Center) analysis, incident response, and threat hunting. This certification exam is ideal for those who are looking to enhance their skills and knowledge in the field of cybersecurity and want to prove their proficiency in SOC operations. The exam covers a range of topics related to SOC analysis, including network security, threat intelligence, and incident response.

 

NEW QUESTION # 25
Jony, a security analyst, while monitoring IIS logs, identified events shown in the figure below.

What does this event log indicate?

  • A. XSS Attack
  • B. Parameter Tampering Attack
  • C. SQL Injection Attack
  • D. Directory Traversal Attack

Answer: C

Explanation:


NEW QUESTION # 26
Jony, a security analyst, while monitoring IIS logs, identified events shown in the figure below.

What does this event log indicate?

  • A. XSS Attack
  • B. Parameter Tampering Attack
  • C. Directory Traversal Attack
  • D. SQL Injection Attack

Answer: B


NEW QUESTION # 27
If the SIEM generates the following four alerts at the same time:
I.Firewall blocking traffic from getting into the network alerts
II.SQL injection attempt alerts
III.Data deletion attempt alerts
IV.Brute-force attempt alerts
Which alert should be given least priority as per effective alert triaging?

  • A. I
  • B. II
  • C. IV
  • D. III

Answer: A


NEW QUESTION # 28
Wesley is an incident handler in a company named Maddison Tech. One day, he was learning techniques for eradicating the insecure deserialization attacks.
What among the following should Wesley avoid from considering?

  • A. Understand the security permissions given to serialization and deserialization
  • B. Deserialization of trusted data must cross a trust boundary
  • C. Allow serialization for security-sensitive classes
  • D. Validate untrusted input, which is to be serialized to ensure that serialized data contain only trusted classes

Answer: C


NEW QUESTION # 29
Which of the following tool can be used to filter web requests associated with the SQL Injection attack?

  • A. Nmap
  • B. ZAP proxy
  • C. UrlScan
  • D. Hydra

Answer: C


NEW QUESTION # 30
Which of the following attacks causes sudden changes in file extensions or increase in file renames at rapid speed?

  • A. DHCP starvation Attack
  • B. File Injection Attack
  • C. Ransomware Attack
  • D. DoS Attack

Answer: C


NEW QUESTION # 31
Shawn is a security manager working at Lee Inc Solution. His organization wants to develop threat intelligent strategy plan. As a part of threat intelligent strategy plan, he suggested various components, such as threat intelligence requirement analysis, intelligence and collection planning, asset identification, threat reports, and intelligence buy-in.
Which one of the following components he should include in the above threat intelligent strategy plan to make it effective?

  • A. Threat boosting
  • B. Threat buy-in
  • C. Threat trending
  • D. Threat pivoting

Answer: C

Explanation:


NEW QUESTION # 32
Identify the attack when an attacker by several trial and error can read the contents of a password file present in the restricted etc folder just by manipulating the URL in the browser as shown:
http://www.terabytes.com/process.php./../../../../etc/passwd

  • A. Form Tampering Attack
  • B. Denial-of-Service Attack
  • C. SQL Injection Attack
  • D. Directory Traversal Attack

Answer: C


NEW QUESTION # 33
Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket raised regarding a critical incident and Mike was assigned to handle the incident. During the process of incident handling, at one stage, he has performed incident analysis and validation to check whether the incident is a true incident or a false positive.
Identify the stage in which he is currently in.

  • A. Incident Triage
  • B. Post-Incident Activities
  • C. Incident Disclosure
  • D. Incident Recording and Assignment

Answer: A

Explanation:


NEW QUESTION # 34
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.
Which of the following data source will he use to prepare the dashboard?

  • A. DNS/ Web Server logs with IP addresses.
  • B. Apache/ Web Server logs with IP addresses and Host Name.
  • C. IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.
  • D. DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.

Answer: B


NEW QUESTION # 35
Identify the password cracking attempt involving a precomputed dictionary of plaintext passwords and their corresponding hash values to crack the password.

  • A. Dictionary Attack
  • B. Rainbow Table Attack
  • C. Syllable Attack
  • D. Bruteforce Attack

Answer: A


NEW QUESTION # 36
Which of the following stage executed after identifying the required event sources?

  • A. Defining Rule for the Use Case
  • B. Implementing and Testing the Use Case
  • C. Identifying the monitoring Requirements
  • D. Validating the event source against monitoring requirement

Answer: D


NEW QUESTION # 37
Which of the following is a default directory in a Mac OS X that stores security-related logs?

  • A. /Library/Logs/Sync
  • B. /var/log/cups/access_log
  • C. /private/var/log
  • D. ~/Library/Logs

Answer: D


NEW QUESTION # 38
Daniel is a member of an IRT, which was started recently in a company named Mesh Tech. He wanted to find the purpose and scope of the planned incident response capabilities.
What is he looking for?

  • A. Incident Response Intelligence
  • B. Incident Response Vision
  • C. Incident Response Mission
  • D. Incident Response Resources

Answer: C

Explanation:


NEW QUESTION # 39
Which encoding replaces unusual ASCII characters with "%" followed by the character's two-digit ASCII code expressed in hexadecimal?

  • A. URL Encoding
  • B. Base64 Encoding
  • C. UTF Encoding
  • D. Unicode Encoding

Answer: A


NEW QUESTION # 40
What does the Security Log Event ID 4624 of Windows 10 indicate?

  • A. A share was assessed
  • B. Service added to the endpoint
  • C. New process executed
  • D. An account was successfully logged on

Answer: D


NEW QUESTION # 41
Which of the following data source can be used to detect the traffic associated with Bad Bot User-Agents?

  • A. Router Logs
  • B. Windows Event Log
  • C. Web Server Logs
  • D. Switch Logs

Answer: C


NEW QUESTION # 42
Identify the type of attack, an attacker is attempting on www.example.com website.

  • A. Cross-site Scripting Attack
  • B. Denial-of-Service Attack
  • C. Session Attack
  • D. SQL Injection Attack

Answer: A


NEW QUESTION # 43
......

EC-COUNCIL 312-39 Real 2023 Braindumps Mock Exam Dumps: https://torrentvce.exam4free.com/312-39-valid-dumps.html