Practice 312-39 Cyber Threats Iocs And Attack Methodology questions with full explanations on every answer.
Start practicing
Cyber Threats Iocs And Attack Methodology — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are analyzing a packet capture (PCAP) and find a beaconing pattern with a consistent 30-second interval and jitter of 5%. Which detection strategy is most effective for this IoC?
2In a Windows environment, which artifact would provide the best evidence of 'Lateral Movement' using Pass-the-Hash?
3An analyst notices a spike in outbound traffic to a known sinkhole IP address. What does this indicate?
4A SOC analyst is reviewing logs in a SIEM and notices multiple failed login attempts followed by a successful one from an unknown IP. Which specific IoC category does this activity represent?
5You are tracking a threat actor who uses 'Living off the Land' (LotL) techniques. Which of the following commands is a classic indicator of this methodology?
6A system administrator reports high CPU usage on a server. Upon checking task manager, you find 'svchost.exe' running from a temp folder. What is the most immediate action?
7Which of the following describes the 'Reconnaissance' phase in the Cyber Kill Chain?
8Which of the following is considered a 'Network-based' IoC?
9You are investigating an incident involving a malicious macro embedded in an Excel document. Which Windows process is typically the 'parent' of the malicious payload execution?
10A user complains that their browser homepage has changed. Upon inspection, you find a new, unsigned extension installed. Which attack methodology is this?
11Which TWO of the following are primary goals of the 'Command and Control' (C2) phase?
12During a forensic analysis, you find a 'shimcache' entry indicating an executable ran from a volume that no longer exists. What does this suggest?
13Which TWO of the following are considered indicators of a 'Data Exfiltration' attempt?
14Which THREE of the following are characteristics of 'Advanced Persistent Threat' (APT) attack methodologies?
15Which THREE of the following are commonly monitored artifacts for detecting 'Persistence' mechanisms?
16Which TWO of the following are valid examples of 'Host-based' Indicators of Compromise?
The Cyber Threats Iocs And Attack Methodology domain covers the key concepts tested in this area of the 312-39 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-39 domains — no account required.
The Courseiva 312-39 question bank contains 16 questions in the Cyber Threats Iocs And Attack Methodology domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cyber Threats Iocs And Attack Methodology domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included