Free 312-39 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
ECcouncil (SOC Analyst) 312 39
Q: 1
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to
prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is
coming.
Which of the following data source will he use to prepare the dashboard?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
An organization wants to implement a SIEM deployment architecture. However, they have the
capability to do only log collection and the rest of the SIEM functions must be managed by an MSSP.
Which SIEM deployment architecture will the organization adopt?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
Which of the following is a report writing tool that will help incident handlers to generate efficient
reports on detected incidents during incident response process?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
Sam, a security analyst with INFOSOL INC., while monitoring and analyzing IIS logs, detected an
event matching regex /\\w*((\%27)|(\’))((\%6F)|o|(\%4F))((\%72)|r|(\%52))/ix.
What does this event log indicate?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Which of the following factors determine the choice of SIEM architecture?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
Juliea a SOC analyst, while monitoring logs, noticed large TXT, NULL payloads.
What does this indicate?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Which of the following security technology is used to attract and trap people who attempt
unauthorized or illicit utilization of the host system?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
An organization is implementing and deploying the SIEM with following capabilities.
What kind of SIEM deployment architecture the organization is planning to implement?
What kind of SIEM deployment architecture the organization is planning to implement?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
Banter is a threat analyst in Christine Group of Industries. As a part of the job, he is currently
formatting and structuring the raw data.
He is at which stage of the threat intelligence life cycle?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
Which of the following data source can be used to detect the traffic associated with Bad Bot User-
Agents?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
What does HTTPS Status code 403 represents?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
Which of the following technique involves scanning the headers of IP packets leaving a network to
make sure
that the unauthorized or malicious traffic never leaves the internal network?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
Which of the following data source will a SOC Analyst use to monitor connections to the insecure
ports?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Which of the following directory will contain logs related to printer access?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
Identify the password cracking attempt involving a precomputed dictionary of plaintext passwords
and their corresponding hash values to crack the password.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
According to the Risk Matrix table, what will be the risk level when the probability of an attack is very
high, and the impact of that attack is major?
NOTE: It is mandatory to answer the question before proceeding to the next one.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
Peter, a SOC analyst with Spade Systems, is monitoring and analyzing the router logs of the company
and wanted to check the logs that are generated by access control list numbered 210.
What filter should Peter add to the 'show logging' command to get the required output?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
Identify the attack, where an attacker tries to discover all the possible information about a target
network before launching a further attack.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for
further investigation and confirmation. Charline, after a thorough investigation, confirmed the
incident and assigned it with an initial priority.
What would be her next action according to the SOC workflow?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
Which of the following tool can be used to filter web requests associated with the SQL Injection
attack?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20