4/5 - (1 vote)

The Best 312-39 Exam Study Material and Preparation Test Question Dumps

Get Ready to Pass the 312-39 exam Right Now Using Our EC-COUNCIL CSA Exam Package

NO.36 Rinni, SOC analyst, while monitoring IDS logs detected events shown in the figure below.

What does this event log indicate?

 
 
 
 

NO.37 Which of the following formula represents the risk?

 
 
 
 

NO.38 An attacker exploits the logic validation mechanisms of an e-commerce website. He successfully purchases a product worth $100 for $10 by modifying the URL exchanged between the client and the server.
Original
URL: http://www.buyonline.com/product.aspx?profile=12
&debit=100
Modified URL: http://www.buyonline.com/product.aspx?profile=12
&debit=10
Identify the attack depicted in the above scenario.

 
 
 
 

NO.39 Which of the following are the responsibilities of SIEM Agents?
1.Collecting data received from various devices sending data to SIEM before forwarding it to the central engine.
2.Normalizing data received from various devices sending data to SIEM before forwarding it to the central engine.
3.Co-relating data received from various devices sending data to SIEM before forwarding it to the central engine.
4.Visualizing data received from various devices sending data to SIEM before forwarding it to the central engine.

 
 
 
 

NO.40 Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket raised regarding a critical incident and Mike was assigned to handle the incident. During the process of incident handling, at one stage, he has performed incident analysis and validation to check whether the incident is a true incident or a false positive.
Identify the stage in which he is currently in.

 
 
 
 

NO.41 Daniel is a member of an IRT, which was started recently in a company named Mesh Tech. He wanted to find the purpose and scope of the planned incident response capabilities.
What is he looking for?

 
 
 
 

NO.42 An organization is implementing and deploying the SIEM with following capabilities.

What kind of SIEM deployment architecture the organization is planning to implement?

 
 
 
 

NO.43 If the SIEM generates the following four alerts at the same time:
I.Firewall blocking traffic from getting into the network alerts
II.SQL injection attempt alerts
III.Data deletion attempt alerts
IV.Brute-force attempt alerts
Which alert should be given least priority as per effective alert triaging?

 
 
 
 

NO.44 According to the Risk Matrix table, what will be the risk level when the probability of an attack is very low and the impact of that attack is major?

 
 
 
 

NO.45 Identify the HTTP status codes that represents the server error.

 
 
 
 

NO.46 An attacker, in an attempt to exploit the vulnerability in the dynamically generated welcome page, inserted code at the end of the company’s URL as follows:
http://technosoft.com.com/<script>alert(“WARNING: The application has encountered an error”);</script>.
Identify the attack demonstrated in the above scenario.

 
 
 
 

NO.47 David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not able to find any suspicious events.
This type of incident is categorized into?

 
 
 
 

NO.48 What is the process of monitoring and capturing all data packets passing through a given network using different tools?

 
 
 
 

NO.49 Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for further investigation and confirmation. Charline, after a thorough investigation, confirmed the incident and assigned it with an initial priority.
What would be her next action according to the SOC workflow?

 
 
 
 

NO.50 Which of the following threat intelligence helps cyber security professionals such as security operations managers, network operations center and incident responders to understand how the adversaries are expected to perform the attack on the organization, and the technical capabilities and goals of the attackers along with the attack vectors?

 
 
 
 

NO.51 Rinni, SOC analyst, while monitoring IDS logs detected events shown in the figure below.

What does this event log indicate?

 
 
 
 

NO.52 What does Windows event ID 4740 indicate?

 
 
 
 

NO.53 Which of the following command is used to view iptables logs on Ubuntu and Debian distributions?

 
 
 
 

NO.54 Which of the following contains the performance measures, and proper project and time management details?

 
 
 
 

NO.55 Which of the following security technology is used to attract and trap people who attempt unauthorized or illicit utilization of the host system?

 
 
 
 

NO.56 Chloe, a SOC analyst with Jake Tech, is checking Linux systems logs. She is investigating files at /var/log/ wtmp.
What Chloe is looking at?

 
 
 
 

NO.57 Which of the following data source can be used to detect the traffic associated with Bad Bot User-Agents?

 
 
 
 

NO.58 Shawn is a security manager working at Lee Inc Solution. His organization wants to develop threat intelligent strategy plan. As a part of threat intelligent strategy plan, he suggested various components, such as threat intelligence requirement analysis, intelligence and collection planning, asset identification, threat reports, and intelligence buy-in.
Which one of the following components he should include in the above threat intelligent strategy plan to make it effective?

 
 
 
 

Get Special Discount Offer of 312-39 Certification Exam Sample Questions and Answers: https://www.braindumpstudy.com/312-39_braindumps.html

         

Related Links: myportal.utt.edu.tt www.fotor.com www.stes.tyc.edu.tw www.stes.tyc.edu.tw myportal.utt.edu.tt myportal.utt.edu.tt