
[Oct-2021] Get 100% Real 312-39 Exam Questions, Accurate & Verified PassLeaderVCE Dumps in the Real Exam!
Pass Your EC-COUNCIL CSA Exams Fast. All Top 312-39 Exam Questions Are Covered.
NEW QUESTION 51
Which of the following technique involves scanning the headers of IP packets leaving a network to make sure that the unauthorized or malicious traffic never leaves the internal network?
- A. Rate Limiting
- B. Ingress Filtering
- C. Egress Filtering
- D. Throttling
Answer: C
NEW QUESTION 52
Ray is a SOC analyst in a company named Queens Tech. One Day, Queens Tech is affected by a DoS/DDoS attack. For the containment of this incident, Ray and his team are trying to provide additional bandwidth to the network devices and increasing the capacity of the servers.
What is Ray and his team doing?
- A. Degrading the services
- B. Blocking the Attacks
- C. Diverting the Traffic
- D. Absorbing the Attack
Answer: D
NEW QUESTION 53
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.
Which of the following data source will he use to prepare the dashboard?
- A. DNS/ Web Server logs with IP addresses.
- B. IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.
- C. Apache/ Web Server logs with IP addresses and Host Name.
- D. DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.
Answer: C
NEW QUESTION 54
What does [-n] in the following checkpoint firewall log syntax represents?
fw log [-f [-t]] [-n] [-l] [-o] [-c action] [-h host] [-s starttime] [-e endtime] [-b starttime endtime] [-u unification_scheme_file] [-m unification_mode(initial|semi|raw)] [-a] [-k (alert name|all)] [-g] [logfile]
- A. Speed up the process by not performing IP addresses DNS resolution in the Log files
- B. Display detailed log chains (all the log segments a log record consists of)
- C. Display both the date and the time for each log record
- D. Display account log records only
Answer: A
NEW QUESTION 55
Which of the following command is used to enable logging in iptables?
- A. $ iptables -B INPUT -j LOG
- B. $ iptables -A INPUT -j LOG
- C. $ iptables -B OUTPUT -j LOG
- D. $ iptables -A OUTPUT -j LOG
Answer: D
NEW QUESTION 56
What does Windows event ID 4740 indicate?
- A. A user account was enabled.
- B. A user account was locked out.
- C. A user account was created.
- D. A user account was disabled.
Answer: B
NEW QUESTION 57
Which of the following factors determine the choice of SIEM architecture?
- A. DNS Configuration
- B. SMTP Configuration
- C. DHCP Configuration
- D. Network Topology
Answer: A
NEW QUESTION 58
Daniel is a member of an IRT, which was started recently in a company named Mesh Tech. He wanted to find the purpose and scope of the planned incident response capabilities.
What is he looking for?
- A. Incident Response Mission
- B. Incident Response Vision
- C. Incident Response Intelligence
- D. Incident Response Resources
Answer: D
NEW QUESTION 59
An organization wants to implement a SIEM deployment architecture. However, they have the capability to do only log collection and the rest of the SIEM functions must be managed by an MSSP.
Which SIEM deployment architecture will the organization adopt?
- A. Self-hosted, MSSP Managed
- B. Self-hosted, Jointly Managed
- C. Cloud, MSSP Managed
- D. Self-hosted, Self-Managed
Answer: A
NEW QUESTION 60
An attacker, in an attempt to exploit the vulnerability in the dynamically generated welcome page, inserted code at the end of the company's URL as follows:
http://technosoft.com.com/<script>alert("WARNING: The application has encountered an error");</script>.
Identify the attack demonstrated in the above scenario.
- A. SQL Injection Attack
- B. Denial-of-Service Attack
- C. Cross-site Scripting Attack
- D. Session Attack
Answer: D
NEW QUESTION 61
Which of the following framework describes the essential characteristics of an organization's security engineering process that must exist to ensure good security engineering?
- A. SSE-CMM
- B. COBIT
- C. SOC-CMM
- D. ITIL
Answer: A
NEW QUESTION 62
Which of the following Windows event is logged every time when a user tries to access the "Registry" key?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION 63
Which of the following tool can be used to filter web requests associated with the SQL Injection attack?
- A. UrlScan
- B. Nmap
- C. ZAP proxy
- D. Hydra
Answer: A
NEW QUESTION 64
Harley is working as a SOC analyst with Powell Tech. Powell Inc. is using Internet Information Service (IIS) version 7.0 to host their website.
Where will Harley find the web server logs, if he wants to investigate them for any anomalies?
- A. SystemDrive%\LogFiles\inetpub\logs\W3SVCN
- B. SystemDrive%\ inetpub\LogFiles\logs\W3SVCN
- C. %SystemDrive%\LogFiles\logs\W3SVCN
- D. SystemDrive%\inetpub\logs\LogFiles\W3SVCN
Answer: A
NEW QUESTION 65
Identify the HTTP status codes that represents the server error.
- A. 2XX
- B. 5XX
- C. 4XX
- D. 1XX
Answer: B
NEW QUESTION 66
David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not able to find any suspicious events.
This type of incident is categorized into?
- A. False Negative Incidents
- B. True Positive Incidents
- C. False positive Incidents
- D. True Negative Incidents
Answer: D
NEW QUESTION 67
Which of the following is a Threat Intelligence Platform?
- A. TC Complete
- B. Apility.io
- C. SolarWinds MS
- D. Keepnote
Answer: C
NEW QUESTION 68
Which of the following fields in Windows logs defines the type of event occurred, such as Correlation Hint, Response Time, SQM, WDI Context, and so on?
- A. Keywords
- B. Level
- C. Task Category
- D. Source
Answer: A
NEW QUESTION 69
......
Penetration testers simulate 312-39 exam: https://www.passleadervce.com/EC-COUNCIL-CSA/reliable-312-39-exam-learning-guide.html
Free Test Engine For Certified SOC Analyst (CSA) Certification Exams: https://drive.google.com/open?id=1y-IYV1SHdHX15XmTD0pK9TP-Y-ysel0F