Practice 312-39 Incident Detection And Triage questions with full explanations on every answer.
Start practicing
Incident Detection And Triage — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
What is the purpose of normalizing logs in a SIEM?
2You are designing a correlation rule in Microsoft Sentinel to detect lateral movement. You decide to use KQL to join 'SecurityEvent' and 'SigninLogs'. What is the primary benefit of using a join over a union in this scenario?
3When performing alert triage in a SIEM, which metric is most important for prioritizing incidents based on the potential business impact?
4In ArcSight, a correlation rule is failing to trigger despite matching event patterns. You verify the filter logic is correct. What is the most likely cause?
5You are reviewing a SIEM alert for a 'Brute Force Attack'. You notice the source IP is from a cloud provider. How should you classify this during triage?
6An analyst is investigating an alert regarding an outbound connection to a known malicious IP. Which step should be taken first according to standard triage procedures?
7In IBM QRadar, you notice that a specific log source is not contributing to offense creation. Upon checking the 'Log Activity' tab, you see events are being parsed but are not mapped to any QID. What is the next logical step?
8You are configuring a correlation rule in Splunk Enterprise Security. An analyst reports that too many false positives are triggered for 'Multiple Failed Login Attempts'. What is the most effective way to tune this rule?
9When building a new SIEM use case, what is the first phase of the development lifecycle?
10What is the primary function of a SIEM collector?
11Which SIEM feature is used to group related events into a single incident?
12You are investigating a SIEM alert in Splunk that indicates a potential data exfiltration. The alert uses a threshold of 500MB. How can you improve the accuracy of this alert?
13Which of the following is a key advantage of utilizing a centralized SIEM platform?
14An analyst receives an alert for 'Possible SQL Injection'. The payload contains harmless strings. How should the analyst proceed?
15You are tasked with tuning a SIEM rule that is triggering on legitimate internal vulnerability scanners. What is the best course of action?
16When configuring log ingestion for a cloud service in a SIEM, you notice high latency in alert generation. What is the most likely cause?
17Which of the following describes 'Event Correlation' in a SIEM?
18What does the 'False Positive' rate of a SIEM rule indicate?
19Which component of a SIEM is responsible for identifying patterns in real-time?
20You are reviewing a high-severity alert. Which information is critical to gather during the initial triage?
21You are designing a rule in a SIEM to detect brute force attacks. What is the most important factor when choosing the time window for the rule?
22You are using a SIEM and notice that logs from a critical Windows server are missing. You verify the agent is running and the network is clear. What is the next step?
23You suspect an attacker is using a specific user account to log in from multiple geographic locations simultaneously. Which SIEM capability allows you to detect this?
24What is the primary benefit of 'Threat Intelligence' integration in a SIEM?
25What is a 'log source' in the context of a SIEM?
26You are writing a SIEM query to detect unauthorized access. The query is too slow. What can you do to optimize it?
27You are investigating a SIEM alert and identify a false positive caused by a system administrator's legitimate activity. How should you document this?
28During alert triage, why is it important to check the 'source' of an alert?
29When tuning a correlation rule in IBM QRadar, what is the role of the 'Building Block'?
30What is the purpose of a 'Lookback Window' in a SIEM correlation rule?
31Which of these is a common SIEM data ingestion protocol?
32Which TWO of the following are considered best practices when configuring SIEM alerts to minimize false positives?
33Which THREE of the following are common steps during the 'Alert Triage' process?
34You are configuring a SIEM alert and need to ensure it only triggers during business hours. Where is this configuration typically applied?
35Which THREE of the following factors should be considered when designing a new SIEM use case?
36Which TWO of the following are primary components of a SIEM architecture?
37Which TWO of the following are valid reasons for an analyst to escalate a SIEM incident?
38Which TWO of the following are effective methods for reducing alert volume in a SIEM?
39Which THREE of the following are common challenges in SIEM correlation rule development?
40Which THREE of the following are essential for effective incident response within a SIEM?
41Which TWO of the following are standard log types ingested into a SIEM?
42Which THREE of the following represent 'Contextual Data' that can enrich a SIEM alert?
43In a SIEM, what is the role of a 'Parser'?
44Which of the following is an example of an 'Indicator of Compromise' (IoC)?
45You receive an alert for 'Account Lockout'. You check the logs and see 10 failures in 1 second. What does this suggest?
46What is the purpose of 'Dashboards' in a SIEM?
47You are configuring a SIEM and need to import a list of malicious IPs. What is the correct feature to use?
48You are configuring a correlation rule in IBM QRadar to detect brute-force attacks. You need to ensure that the rule only triggers when a user fails to authenticate five times within a 60-second window across any three distinct source IP addresses. Which building block or configuration approach is most efficient?
49A SOC analyst is reviewing alerts in Microsoft Sentinel. They want to filter the 'SecurityAlert' table to only show alerts with a 'High' severity that originated from a specific resource provider. Which KQL operator should be used?
50You are managing a SIEM and notice a massive spike in 'false positive' alerts originating from a legacy vulnerability scanner. What is the best practice for tuning these alerts without losing visibility into the scanner's activity?
51You are designing a correlation rule in an ArcSight ESM environment. You need to aggregate events based on a 'SessionID' field, but the 'SessionID' is not explicitly parsed in the incoming CEF logs. What must you do first?
52A SOC analyst is tasked with reducing 'alert fatigue' by categorizing alerts based on their MITRE ATT&CK technique mapping. Which phase of the incident response lifecycle is the analyst performing?
53You are performing alert triage on a potential data exfiltration attempt. The SIEM shows 50GB of data transferred to a known cloud storage IP address. What is the most important next step in your triage process?
54When designing correlation rules for an organization, which TWO of the following practices are recommended to minimize false positives?
55Which THREE of the following are common attributes used to prioritize security alerts during the triage process?
56Which TWO of the following are key components of a successful SIEM use case development process?
57You are reviewing a SIEM alert and see a 'Successful login' from an unusual location. What is the next logical action?
The Incident Detection And Triage domain covers the key concepts tested in this area of the 312-39 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-39 domains — no account required.
The Courseiva 312-39 question bank contains 57 questions in the Incident Detection And Triage domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Incident Detection And Triage domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included