312-39 Practice Exam Tests Latest Updated on Oct-2021 [Q32-Q56]

Share

312-39 Practice Exam Tests Latest Updated on Oct-2021

Pass 312-39 Exam in First Attempt Guaranteed Dumps!

NEW QUESTION 32
Which of the following is a report writing tool that will help incident handlers to generate efficient reports on detected incidents during incident response process?

  • A. threat_note
  • B. MagicTree
  • C. IntelMQ
  • D. Malstrom

Answer: C

 

NEW QUESTION 33
Which of the following formula represents the risk?

  • A. Risk = Likelihood * Impact * Asset Value
  • B. Risk = Likelihood * Severity * Asset Value
  • C. Risk = Likelihood * Impact * Severity
  • D. Risk = Likelihood * Consequence * Severity

Answer: D

 

NEW QUESTION 34
Which of the following formula is used to calculate the EPS of the organization?

  • A. EPS = number of correlated events / time in seconds
  • B. EPS = number of normalized events / time in seconds
  • C. EPS = number of security events / time in seconds
  • D. EPS = average number of correlated events / time in seconds

Answer: D

 

NEW QUESTION 35
Harley is working as a SOC analyst with Powell Tech. Powell Inc. is using Internet Information Service (IIS) version 7.0 to host their website.
Where will Harley find the web server logs, if he wants to investigate them for any anomalies?

  • A. SystemDrive%\LogFiles\inetpub\logs\W3SVCN
  • B. SystemDrive%\ inetpub\LogFiles\logs\W3SVCN
  • C. %SystemDrive%\LogFiles\logs\W3SVCN
  • D. SystemDrive%\inetpub\logs\LogFiles\W3SVCN

Answer: A

 

NEW QUESTION 36
Which of the following process refers to the discarding of the packets at the routing level without informing the source that the data did not reach its intended recipient?

  • A. Rate Limiting
  • B. Black Hole Filtering
  • C. Drop Requests
  • D. Load Balancing

Answer: B

 

NEW QUESTION 37
Which of the following is a correct flow of the stages in an incident handling and response (IH&R) process?

  • A. Incident Triage -> Eradication -> Containment -> Incident Recording -> Preparation -> Recovery -> Post-Incident Activities
  • B. Preparation -> Incident Recording -> Incident Triage -> Containment -> Eradication -> Recovery -> Post-Incident Activities
  • C. Incident Recording -> Preparation -> Containment -> Incident Triage -> Recovery -> Eradication -> Post-Incident Activities
  • D. Containment -> Incident Recording -> Incident Triage -> Preparation -> Recovery -> Eradication -> Post-Incident Activities

Answer: B

 

NEW QUESTION 38
Which of the following service provides phishing protection and content filtering to manage the Internet experience on and off your network with the acceptable use or compliance policies?

  • A. I-Blocklist
  • B. Apility.io
  • C. OpenDNS
  • D. Malstrom

Answer: C

 

NEW QUESTION 39
Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket raised regarding a critical incident and Mike was assigned to handle the incident. During the process of incident handling, at one stage, he has performed incident analysis and validation to check whether the incident is a true incident or a false positive.
Identify the stage in which he is currently in.

  • A. Incident Recording and Assignment
  • B. Incident Disclosure
  • C. Incident Triage
  • D. Post-Incident Activities

Answer: A

 

NEW QUESTION 40
Which of the following tool is used to recover from web application incident?

  • A. Smoothwall SWG
  • B. Symantec Secure Web Gateway
  • C. CrowdStrike FalconTM Orchestrator
  • D. Proxy Workbench

Answer: B

 

NEW QUESTION 41
An organization wants to implement a SIEM deployment architecture. However, they have the capability to do only log collection and the rest of the SIEM functions must be managed by an MSSP.
Which SIEM deployment architecture will the organization adopt?

  • A. Self-hosted, MSSP Managed
  • B. Self-hosted, Jointly Managed
  • C. Cloud, MSSP Managed
  • D. Self-hosted, Self-Managed

Answer: A

 

NEW QUESTION 42
Which of the following directory will contain logs related to printer access?

  • A. /var/log/cups/Printeraccess_log file
  • B. /var/log/cups/access_log file
  • C. /var/log/cups/accesslog file
  • D. /var/log/cups/Printer_log file

Answer: D

 

NEW QUESTION 43
An organization is implementing and deploying the SIEM with following capabilities.

What kind of SIEM deployment architecture the organization is planning to implement?

  • A. Cloud, MSSP Managed
  • B. Self-hosted, Jointly Managed
  • C. Self-hosted, MSSP Managed
  • D. Self-hosted, Self-Managed

Answer: A

 

NEW QUESTION 44
Which of the following attack can be eradicated by disabling of "allow_url_fopen and allow_url_include" in the php.ini file?

  • A. URL Injection Attacks
  • B. LDAP Injection Attacks
  • C. Command Injection Attacks
  • D. File Injection Attacks

Answer: A

 

NEW QUESTION 45
Which of the following technique involves scanning the headers of IP packets leaving a network to make sure that the unauthorized or malicious traffic never leaves the internal network?

  • A. Rate Limiting
  • B. Ingress Filtering
  • C. Egress Filtering
  • D. Throttling

Answer: C

 

NEW QUESTION 46
Which of the following tool can be used to filter web requests associated with the SQL Injection attack?

  • A. UrlScan
  • B. Nmap
  • C. ZAP proxy
  • D. Hydra

Answer: A

 

NEW QUESTION 47
If the SIEM generates the following four alerts at the same time:
I.Firewall blocking traffic from getting into the network alerts
II.SQL injection attempt alerts
III.Data deletion attempt alerts
IV.Brute-force attempt alerts
Which alert should be given least priority as per effective alert triaging?

  • A. III
  • B. IV
  • C. II
  • D. I

Answer: D

 

NEW QUESTION 48
John, a threat analyst at GreenTech Solutions, wants to gather information about specific threats against the organization. He started collecting information from various sources, such as humans, social media, chat room, and so on, and created a report that contains malicious activity.
Which of the following types of threat intelligence did he use?

  • A. Strategic Threat Intelligence
  • B. Technical Threat Intelligence
  • C. Tactical Threat Intelligence
  • D. Operational Threat Intelligence

Answer: D

 

NEW QUESTION 49
Which of the following Windows event is logged every time when a user tries to access the "Registry" key?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

 

NEW QUESTION 50
Which of the following technique protects from flooding attacks originated from the valid prefixes (IP addresses) so that they can be traced to its true source?

  • A. Rate Limiting
  • B. Ingress Filtering
  • C. Egress Filtering
  • D. Throttling

Answer: B

 

NEW QUESTION 51
Which of the following Windows Event Id will help you monitors file sharing across the network?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

 

NEW QUESTION 52
Which of the following threat intelligence is used by a SIEM for supplying the analysts with context and
"situational awareness" by using threat actor TTPs, malware campaigns, tools used by threat actors.
1.Strategic threat intelligence
2.Tactical threat intelligence
3.Operational threat intelligence
4.Technical threat intelligence

  • A. 2 and 3
  • B. 1 and 2
  • C. 3 and 4
  • D. 1 and 3

Answer: A

 

NEW QUESTION 53
Peter, a SOC analyst with Spade Systems, is monitoring and analyzing the router logs of the company and wanted to check the logs that are generated by access control list numbered 210.
What filter should Peter add to the 'show logging' command to get the required output?

  • A. show logging | access 210
  • B. show logging | include 210
  • C. show logging | forward 210
  • D. show logging | route 210

Answer: B

 

NEW QUESTION 54
Which of the following framework describes the essential characteristics of an organization's security engineering process that must exist to ensure good security engineering?

  • A. SSE-CMM
  • B. COBIT
  • C. SOC-CMM
  • D. ITIL

Answer: A

 

NEW QUESTION 55
Which of the following is a set of standard guidelines for ongoing development, enhancement, storage, dissemination and implementation of security standards for account data protection?

  • A. PCI-DSS
  • B. HIPAA
  • C. FISMA
  • D. DARPA

Answer: A

 

NEW QUESTION 56
......

EC-COUNCIL CSA  Free Certification Exam Material from Real4dumps with 102 Questions: https://www.real4dumps.com/312-39_examcollection.html

312-39 Dumps Full Questions - Exam Study Guide: https://drive.google.com/open?id=1qbKUak7BMYUNYqZRbPm4WtJBS9A2_4Z2