312-39 Free Exam Study Guide! (Updated 102 Questions) [Q21-Q46]

Share

312-39 Free Exam Study Guide! (Updated 102 Questions)

312-39 Dumps for EC-COUNCIL CSA Certified Exam Questions and Answer

NEW QUESTION 21
Which of the following event detection techniques uses User and Entity Behavior Analytics (UEBA)?

  • A. Rule-based detection
  • B. Anomaly-based detection
  • C. Heuristic-based detection
  • D. Signature-based detection

Answer: B

 

NEW QUESTION 22
Identify the HTTP status codes that represents the server error.

  • A. 4XX
  • B. 2XX
  • C. 5XX
  • D. 1XX

Answer: C

 

NEW QUESTION 23
Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry:
May 06 2018 21:27:27 asa 1: %ASA -5 - 11008: User 'enable_15' executed the 'configure term' command What does the security level in the above log indicates?

  • A. Critical condition message
  • B. Informational message
  • C. Normal but significant message
  • D. Warning condition message

Answer: C

Explanation:

 

NEW QUESTION 24
Which of the following attacks causes sudden changes in file extensions or increase in file renames at rapid speed?

  • A. File Injection Attack
  • B. DoS Attack
  • C. Ransomware Attack
  • D. DHCP starvation Attack

Answer: C

 

NEW QUESTION 25
Juliea a SOC analyst, while monitoring logs, noticed large TXT, NULL payloads.
What does this indicate?

  • A. Concurrent VPN Connections Attempt
  • B. DHCP Starvation Attempt
  • C. DNS Exfiltration Attempt
  • D. Covering Tracks Attempt

Answer: C

 

NEW QUESTION 26
What is the correct sequence of SOC Workflow?

  • A. Collect, Ingest, Document, Validate, Report, Respond
  • B. Collect, Respond, Validate, Ingest, Report, Document
  • C. Collect, Ingest, Validate, Document, Report, Respond
  • D. Collect, Ingest, Validate, Report, Respond, Document

Answer: C

 

NEW QUESTION 27
According to the Risk Matrix table, what will be the risk level when the probability of an attack is very low and the impact of that attack is major?

  • A. Extreme
  • B. Low
  • C. Medium
  • D. High

Answer: C

Explanation:
Explanation
Graphical user interface, application, Teams Description automatically generated

 

NEW QUESTION 28
Daniel is a member of an IRT, which was started recently in a company named Mesh Tech. He wanted to find the purpose and scope of the planned incident response capabilities.
What is he looking for?

  • A. Incident Response Mission
  • B. Incident Response Intelligence
  • C. Incident Response Resources
  • D. Incident Response Vision

Answer: C

 

NEW QUESTION 29
Which of the following attack can be eradicated by disabling of "allow_url_fopen and allow_url_include" in the php.ini file?

  • A. URL Injection Attacks
  • B. File Injection Attacks
  • C. Command Injection Attacks
  • D. LDAP Injection Attacks

Answer: B

Explanation:

 

NEW QUESTION 30
What is the correct sequence of SOC Workflow?

  • A. Collect, Ingest, Document, Validate, Report, Respond
  • B. Collect, Respond, Validate, Ingest, Report, Document
  • C. Collect, Ingest, Validate, Document, Report, Respond
  • D. Collect, Ingest, Validate, Report, Respond, Document

Answer: D

Explanation:

 

NEW QUESTION 31
Which of the following fields in Windows logs defines the type of event occurred, such as Correlation Hint, Response Time, SQM, WDI Context, and so on?

  • A. Level
  • B. Task Category
  • C. Keywords
  • D. Source

Answer: C

 

NEW QUESTION 32
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.
Which of the following data source will he use to prepare the dashboard?

  • A. DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.
  • B. IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.
  • C. DNS/ Web Server logs with IP addresses.
  • D. Apache/ Web Server logs with IP addresses and Host Name.

Answer: A

Explanation:

 

NEW QUESTION 33
Which of the following Windows event is logged every time when a user tries to access the "Registry" key?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

Explanation:

 

NEW QUESTION 34
Which of the following formula is used to calculate the EPS of the organization?

  • A. EPS = number of correlated events / time in seconds
  • B. EPS = average number of correlated events / time in seconds
  • C. EPS = number of security events / time in seconds
  • D. EPS = number of normalized events / time in seconds

Answer: B

 

NEW QUESTION 35
What does the Security Log Event ID 4624 of Windows 10 indicate?

  • A. A share was assessed
  • B. An account was successfully logged on
  • C. New process executed
  • D. Service added to the endpoint

Answer: B

 

NEW QUESTION 36
Which of the following is a default directory in a Mac OS X that stores security-related logs?

  • A. /private/var/log
  • B. /var/log/cups/access_log
  • C. /Library/Logs/Sync
  • D. ~/Library/Logs

Answer: D

 

NEW QUESTION 37
InfoSystem LLC, a US-based company, is establishing an in-house SOC. John has been given the responsibility to finalize strategy, policies, and procedures for the SOC.
Identify the job role of John.

  • A. Chief Information Security Officer (CISO)
  • B. Security Engineer
  • C. Security Analyst - L2
  • D. Security Analyst - L1

Answer: A

 

NEW QUESTION 38
In which log collection mechanism, the system or application sends log records either on the local disk or over the network.

  • A. rule-based
  • B. signature-based
  • C. push-based
  • D. pull-based

Answer: A

 

NEW QUESTION 39
Which of the following is a default directory in a Mac OS X that stores security-related logs?

  • A. /private/var/log
  • B. /var/log/cups/access_log
  • C. ~/Library/Logs
  • D. /Library/Logs/Sync

Answer: A

Explanation:

 

NEW QUESTION 40
Which of the following process refers to the discarding of the packets at the routing level without informing the source that the data did not reach its intended recipient?

  • A. Rate Limiting
  • B. Load Balancing
  • C. Black Hole Filtering
  • D. Drop Requests

Answer: C

 

NEW QUESTION 41
Which of the following directory will contain logs related to printer access?

  • A. /var/log/cups/Printer_log file
  • B. /var/log/cups/access_log file
  • C. /var/log/cups/accesslog file
  • D. /var/log/cups/Printeraccess_log file

Answer: A

 

NEW QUESTION 42
Wesley is an incident handler in a company named Maddison Tech. One day, he was learning techniques for eradicating the insecure deserialization attacks.
What among the following should Wesley avoid from considering?

  • A. Deserialization of trusted data must cross a trust boundary
  • B. Allow serialization for security-sensitive classes
  • C. Understand the security permissions given to serialization and deserialization
  • D. Validate untrusted input, which is to be serialized to ensure that serialized data contain only trusted classes

Answer: B

 

NEW QUESTION 43
In which phase of Lockheed Martin's - Cyber Kill Chain Methodology, adversary creates a deliverable malicious payload using an exploit and a backdoor?

  • A. Weaponization
  • B. Reconnaissance
  • C. Exploitation
  • D. Delivery

Answer: D

 

NEW QUESTION 44
Identify the type of attack, an attacker is attempting on www.example.com website.

  • A. Cross-site Scripting Attack
  • B. Session Attack
  • C. SQL Injection Attack
  • D. Denial-of-Service Attack

Answer: A

 

NEW QUESTION 45
Which of the following can help you eliminate the burden of investigating false positives?

  • A. Keeping default rules
  • B. Treating every alert as high level
  • C. Ingesting the context data
  • D. Not trusting the security devices

Answer: A

 

NEW QUESTION 46
......

Use Real 312-39 Dumps - 100% Free 312-39 Exam Dumps: https://www.prep4king.com/312-39-exam-prep-material.html

Realistic Verified 312-39 exam dumps Q&As - 312-39 Free Update: https://drive.google.com/open?id=1j_FJ4ObJXJbuIy-kLw87sCi3wXd3dOve