Verified 312-39 exam dumps Q&As with Correct 102 Questions and Answers [Q29-Q48]

Share

Verified 312-39 exam dumps Q&As with Correct 102 Questions and Answers

EC-COUNCIL 312-39 Test Engine PDF - All Free Dumps from DumpsTorrent

NEW QUESTION 29
Chloe, a SOC analyst with Jake Tech, is checking Linux systems logs. She is investigating files at /var/log/ wtmp.
What Chloe is looking at?

  • A. Login records
  • B. General message and system-related stuff
  • C. Error log
  • D. System boot log

Answer: A

 

NEW QUESTION 30
Which of the following fields in Windows logs defines the type of event occurred, such as Correlation Hint, Response Time, SQM, WDI Context, and so on?

  • A. Source
  • B. Task Category
  • C. Keywords
  • D. Level

Answer: C

 

NEW QUESTION 31
Jane, a security analyst, while analyzing IDS logs, detected an event matching Regex
/((\%3C)|<)((\%69)|i|(\% 49))((\%6D)|m|(\%4D))((\%67)|g|(\%47))[^\n]+((\%3E)|>)/|.
What does this event log indicate?

  • A. XSS Attack
  • B. Parameter Tampering Attack
  • C. SQL Injection Attack
  • D. Directory Traversal Attack

Answer: A

 

NEW QUESTION 32
Which of the following framework describes the essential characteristics of an organization's security engineering process that must exist to ensure good security engineering?

  • A. SSE-CMM
  • B. COBIT
  • C. SOC-CMM
  • D. ITIL

Answer: A

 

NEW QUESTION 33
Which of the following Windows event is logged every time when a user tries to access the "Registry" key?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

 

NEW QUESTION 34
Juliea a SOC analyst, while monitoring logs, noticed large TXT, NULL payloads.
What does this indicate?

  • A. Covering Tracks Attempt
  • B. Concurrent VPN Connections Attempt
  • C. DNS Exfiltration Attempt
  • D. DHCP Starvation Attempt

Answer: C

 

NEW QUESTION 35
Identify the password cracking attempt involving a precomputed dictionary of plaintext passwords and their corresponding hash values to crack the password.

  • A. Syllable Attack
  • B. Dictionary Attack
  • C. Bruteforce Attack
  • D. Rainbow Table Attack

Answer: B

 

NEW QUESTION 36
Sam, a security analyst with INFOSOL INC., while monitoring and analyzing IIS logs, detected an event matching regex /\\w*((\%27)|(\'))((\%6F)|o|(\%4F))((\%72)|r|(\%52))/ix.
What does this event log indicate?

  • A. SQL Injection Attack
  • B. Parameter Tampering Attack
  • C. XSS Attack
  • D. Directory Traversal Attack

Answer: A

 

NEW QUESTION 37
Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry:
May 06 2018 21:27:27 asa 1: %ASA -5 - 11008: User 'enable_15' executed the 'configure term' command What does the security level in the above log indicates?

  • A. Critical condition message
  • B. Warning condition message
  • C. Normal but significant message
  • D. Informational message

Answer: B

 

NEW QUESTION 38
Which of the following attack inundates DHCP servers with fake DHCP requests to exhaust all available IP addresses?

  • A. DHCP Cache Poisoning
  • B. DHCP Spoofing Attack
  • C. DHCP Starvation Attacks
  • D. DHCP Port Stealing

Answer: C

 

NEW QUESTION 39
What is the correct sequence of SOC Workflow?

  • A. Collect, Ingest, Validate, Report, Respond, Document
  • B. Collect, Ingest, Validate, Document, Report, Respond
  • C. Collect, Ingest, Document, Validate, Report, Respond
  • D. Collect, Respond, Validate, Ingest, Report, Document

Answer: B

 

NEW QUESTION 40
In which phase of Lockheed Martin's - Cyber Kill Chain Methodology, adversary creates a deliverable malicious payload using an exploit and a backdoor?

  • A. Weaponization
  • B. Exploitation
  • C. Reconnaissance
  • D. Delivery

Answer: D

 

NEW QUESTION 41
Which of the following attack can be eradicated by disabling of "allow_url_fopen and allow_url_include" in the php.ini file?

  • A. URL Injection Attacks
  • B. File Injection Attacks
  • C. Command Injection Attacks
  • D. LDAP Injection Attacks

Answer: A

 

NEW QUESTION 42
Which of the log storage method arranges event logs in the form of a circular buffer?

  • A. FIFO
  • B. wrapping
  • C. LIFO
  • D. non-wrapping

Answer: A

 

NEW QUESTION 43
Which of the following threat intelligence is used by a SIEM for supplying the analysts with context and
"situational awareness" by using threat actor TTPs, malware campaigns, tools used by threat actors.
1.Strategic threat intelligence
2.Tactical threat intelligence
3.Operational threat intelligence
4.Technical threat intelligence

  • A. 1 and 2
  • B. 1 and 3
  • C. 2 and 3
  • D. 3 and 4

Answer: C

 

NEW QUESTION 44
Harley is working as a SOC analyst with Powell Tech. Powell Inc. is using Internet Information Service (IIS) version 7.0 to host their website.
Where will Harley find the web server logs, if he wants to investigate them for any anomalies?

  • A. SystemDrive%\ inetpub\LogFiles\logs\W3SVCN
  • B. SystemDrive%\LogFiles\inetpub\logs\W3SVCN
  • C. SystemDrive%\inetpub\logs\LogFiles\W3SVCN
  • D. %SystemDrive%\LogFiles\logs\W3SVCN

Answer: B

 

NEW QUESTION 45
Which of the following process refers to the discarding of the packets at the routing level without informing the source that the data did not reach its intended recipient?

  • A. Load Balancing
  • B. Rate Limiting
  • C. Black Hole Filtering
  • D. Drop Requests

Answer: C

 

NEW QUESTION 46
The Syslog message severity levels are labelled from level 0 to level 7.
What does level 0 indicate?

  • A. Emergency
  • B. Alert
  • C. Notification
  • D. Debugging

Answer: C

 

NEW QUESTION 47
According to the Risk Matrix table, what will be the risk level when the probability of an attack is very low and the impact of that attack is major?

  • A. Extreme
  • B. Low
  • C. Medium
  • D. High

Answer: B

 

NEW QUESTION 48
......


The EC-Council 312-39 exam is designed to evaluate and validate the extensive knowledge and skills of the candidates in the job tasks associated with the SOC Analyst role. This test is the first step towards becoming an active player in the security operations center. The potential individuals for the exam demonstrate the in-demand and trending technical skills in carrying out the entry-level and mid-level operations. The students will be measured based on their expertise in log correlation and management, advanced incident detection, SIEM deployment, incident detection, incident response, and management of different SOC processes.

 

100% Passing Guarantee - Brilliant 312-39 Exam Questions PDF: https://www.dumpstorrent.com/312-39-exam-dumps-torrent.html

Get New 312-39 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1PJHr20vUU1yCBCr2or-RFLCtnuKNGdDP