Practice 312-39 Incident Response questions with full explanations on every answer.
Start practicing
Incident Response — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
A SIEM alert indicates multiple failed logins followed by a successful login from a new IP in Splunk Enterprise Security. As a first responder, which dashboard should you navigate to in order to verify the MITRE ATT&CK mapping of this behavior?
2While using ServiceNow Security Incident Response (SIR), you need to escalate a ticket. What is the standard process to ensure the security manager receives notification?
3During incident triage, you realize an alert is a False Positive. What is the most appropriate action to take within the SIEM ticketing system?
4You are triaging an alert in CrowdStrike Falcon. An endpoint shows a 'Suspicious File' detection. To verify the process tree and identify the parent process, which view do you use?
5You are managing a containment procedure for an external C2 callback. Which firewall rule configuration is most effective for immediate containment?
6A suspicious PowerShell script is found on an endpoint. Which tool would you use to perform volatile memory analysis to identify if the script injected malicious code?
7During a suspected malware incident, a SOC analyst needs to isolate an infected workstation using Microsoft Defender for Endpoint. Which specific action should the analyst select within the Device inventory dashboard?
8You are using an EDR to hunt for persistent scheduled tasks. Which artifact should you analyze to see tasks created within the last 24 hours?
9What is the primary purpose of a 'War Room' during a major incident?
10You need to export a PCAP for a suspicious network flow. Using Wireshark, which filter would you use to isolate traffic from a specific suspicious source IP 192.168.1.50?
11When dealing with a ransomware incident, why should you prioritize disconnecting the host from the network over immediate rebooting?
12During an investigation, you need to perform a live acquisition of a suspect's system memory using FTK Imager. What is the correct order of operations to maintain integrity?
13Which document should you reference first to determine the communication path during a high-severity security incident?
14In the NIST Incident Response lifecycle, which phase involves the identification of the incident type and scope?
15An analyst is reviewing logs in Splunk to investigate a potential exfiltration event. Which field should the analyst focus on to identify the volume of data sent to an external IP?
16You are remediating a compromised web server. After identifying the web shell, what is the next step to prevent further access?
17In the context of the MITRE ATT&CK framework, what is the primary goal of the 'Command and Control' tactic?
18You are performing triage for an alert involving unauthorized access to an S3 bucket. Which service would you consult to review the API calls made to that bucket?
19While analyzing an incident involving a malicious domain, you need to determine when the domain was registered. Which database should you query?
20During a suspected lateral movement incident, you observe successful SMB sessions between two workstations. Which tool in Windows can be used to view these active sessions?
21You are analyzing an alert for a suspicious PowerShell command. Which logging setting must be enabled on Windows endpoints to capture the full command-line arguments?
22What is the primary function of an IOC (Indicator of Compromise) in an incident?
23Which document is essential for recording every action taken during an incident for legal and audit purposes?
24When an analyst suspects that a malicious user is using a VPN to hide their source IP, which technique is most helpful for attribution?
25You are investigating a data exfiltration incident. Which protocol's logs would most likely show large volumes of data being moved to a cloud storage provider?
26What is the primary goal of the 'Eradication' phase in incident response?
27What is the main objective of the 'Post-Incident Activity' phase?
28You are auditing user access logs for a potential privilege escalation. What indicates that a user has successfully used 'runas' to switch context?
29During a phishing investigation, you receive a suspicious link. Which safety measure should you use to analyze the link?
30You need to verify if an executable is malicious. Which site is most effective for checking the hash against multiple antivirus engines?
31During a suspected breach, you identify a rogue process running on a Linux server. Which command identifies the network socket associated with this process?
32Which TWO types of evidence should be collected during the identification phase of an incident?
33Which TWO steps are part of the 'Preparation' phase of the incident response process?
34You notice an anomaly in your DNS traffic. Which type of DNS record is commonly associated with DNS tunneling for command and control?
35A ticket is assigned to you with high priority. What is the first thing you should do?
36You are investigating a suspicious login. Which attribute in the Azure AD sign-in logs helps determine if the user successfully authenticated using MFA?
37Which TWO pieces of information are critical to include in an initial incident ticket?
38Which TWO methods are commonly used to achieve persistence on a Windows host?
39Which TWO actions should be taken immediately upon identifying an active malware infection on a workstation?
40Which TWO types of logs are most useful for detecting lateral movement?
41Which THREE factors should be considered when determining the severity level of an incident?
42Which THREE items should be included in a standard incident containment report?
43Which TWO items are part of the 'Lessons Learned' process?
44Which THREE tools are typically used for forensic memory analysis?
45Which THREE actions are appropriate during the eradication phase of a malware incident?
46Which THREE factors contribute to 'dwell time' in a security incident?
47Which THREE elements are essential in an incident notification email to senior management?
48Which TWO indicators should an analyst watch for in a potential phishing campaign?
49Which THREE actions are part of the 'Recovery' phase?
The Incident Response domain covers the key concepts tested in this area of the 312-39 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-39 domains — no account required.
The Courseiva 312-39 question bank contains 49 questions in the Incident Response domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Incident Response domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included