Eccouncil 312-39 practice test

Certified SOC Analyst Exam

Last exam update: Jul 20 ,2024
Page 1 out of 7. Viewing questions 1-15 out of 100

Question 1

Which of the following attack can be eradicated by converting all non-alphanumeric characters to
HTML character entities before displaying the user input in search engines and forums?

  • A. Broken Access Control Attacks
  • B. Web Services Attacks
  • C. XSS Attacks
  • D. Session Management Attacks
Mark Question:
Answer:

C

User Votes:
A
50%
B 1 votes
50%
C 2 votes
50%
D 1 votes
50%

Reference:
https://ktflash.gitbooks.io/ceh_v9/content/125_countermeasures.html

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 2

Which attack works like a dictionary attack, but adds some numbers and symbols to the words from
the dictionary and tries to crack the password?

  • A. Hybrid Attack
  • B. Bruteforce Attack
  • C. Rainbow Table Attack
  • D. Birthday Attack
Mark Question:
Answer:

B

User Votes:
A 1 votes
50%
B 1 votes
50%
C
50%
D
50%

Reference:
https://www.techrepublic.com/article/brute-force-and-dictionary-attacks-a-cheat-sheet/

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

Jony , a security analyst, while monitoring IIS logs, identified events shown in the figure below.

What does this event log indicate?

  • A. Parameter Tampering Attack
  • B. XSS Attack
  • C. Directory Traversal Attack
  • D. SQL Injection Attack
Mark Question:
Answer:

A

User Votes:
A 1 votes
50%
B
50%
C
50%
D 1 votes
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

Identify the HTTP status codes that represents the server error.

  • A. 2XX
  • B. 4XX
  • C. 1XX
  • D. 5XX
Mark Question:
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D 2 votes
50%

Reference:
https://www.tutorialspoint.com/http/http_status_codes.htm

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

Emmanuel is working as a SOC analyst in a company named Tobey Tech. The manager of Tobey Tech
recently recruited an Incident Response Team (IRT) for his company. In the process of collaboration
with the IRT, Emmanuel just escalated an incident to the IRT.
What is the first step that the IRT will do to the incident escalated by Emmanuel?

  • A. Incident Analysis and Validation
  • B. Incident Recording
  • C. Incident Classification
  • D. Incident Prioritization
Mark Question:
Answer:

C

User Votes:
A 1 votes
50%
B 1 votes
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not
able to find any suspicious events.
This type of incident is categorized into ?

  • A. True Positive Incidents
  • B. False positive Incidents
  • C. True Negative Incidents
  • D. False Negative Incidents
Mark Question:
Answer:

C

User Votes:
A
50%
B 1 votes
50%
C
50%
D 1 votes
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

Which of the following service provides phishing protection and content filtering to manage the
Internet experience on and off your network with the acceptable use or compliance policies?

  • A. Apility.io
  • B. Malstrom
  • C. OpenDNS
  • D. I-Blocklist
Mark Question:
Answer:

C

User Votes:
A
50%
B
50%
C 1 votes
50%
D
50%

Reference:
https://www.spamtitan.com/web-filtering/category/cybersecurity-advice/

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

InfoSystem LLC, a US-based company, is establishing an in-house SOC. John has been given the
responsibility to finalize strategy, policies, and procedures for the SOC.
Identify the job role of John.

  • A. Security Analyst – L1
  • B. Chief Information Security Officer (CISO)
  • C. Security Engineer
  • D. Security Analyst – L2
Mark Question:
Answer:

B

User Votes:
A
50%
B 1 votes
50%
C
50%
D
50%

Reference:
https://www.exabeam.com/security-operations-center/security-operations-center-roles-
and- responsibilities/

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 9

If the SIEM generates the following four alerts at the same time:
I. Firewall blocking traffic from getting into the network alerts
II. SQL injection attempt alerts
III. Data deletion attempt alerts
IV. Brute-force attempt alerts
Which alert should be given least priority as per effective alert triaging?

  • A. III
  • B. IV
  • C. II
  • D. I
Mark Question:
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D 1 votes
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

Which of the following threat intelligence helps cyber security professionals such as security
operations managers, network operations center and incident responders to understand how the
adversaries are expected to perform the attack on the organization, and the technical capabilities
and goals of the attackers along with the attack vectors?

  • A. Analytical Threat Intelligence
  • B. Operational Threat Intelligence
  • C. Strategic Threat Intelligence
  • D. Tactical Threat Intelligence
Mark Question:
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D 1 votes
50%

Reference:
https://info-savvy.com/types-of-threat-intelligence/

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11

Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for
further investigation and confirmation. Charline, after a thorough investigation, confirmed the
incident and assigned it with an initial priority.
What would be her next action according to the SOC workflow?

  • A. She should immediately escalate this issue to the management
  • B. She should immediately contact the network administrator to solve the problem
  • C. She should communicate this incident to the media immediately
  • D. She should formally raise a ticket and forward it to the IRT
Mark Question:
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D 1 votes
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

Which of the following tool can be used to filter web requests associated with the SQL Injection
attack?

  • A. Nmap
  • B. UrlScan
  • C. ZAP proxy
  • D. Hydra
Mark Question:
Answer:

B

User Votes:
A
50%
B 1 votes
50%
C
50%
D
50%

Reference:
https://aip.scitation.org/doi/pdf/10.1063/1.4982570

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 13

Which of the following process refers to the discarding of the packets at the routing level without
informing the source that the data did not reach its intended recipient?

  • A. Load Balancing
  • B. Rate Limiting
  • C. Black Hole Filtering
  • D. Drop Requests
Mark Question:
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Reference:
https://en.wikipedia.org/wiki/Black_hole_(networking)#:~:text=In%20networking%2C%20black%
20holes%20refer,not%20reach%20its%20intended%20recipient.

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to
prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is
coming.
Which of the following data source will he use to prepare the dashboard?

  • A. DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.
  • B. IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.
  • C. DNS/ Web Server logs with IP addresses.
  • D. Apache/ Web Server logs with IP addresses and Host Name.
Mark Question:
Answer:

D

User Votes:
A 1 votes
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 15

Which of the following contains the performance measures, and proper project and time
management details?

  • A. Incident Response Policy
  • B. Incident Response Tactics
  • C. Incident Response Process
  • D. Incident Response Procedures
Mark Question:
Answer:

D

User Votes:
A 1 votes
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000
To page 2