Practice 312-39 Proactive Threat Detection questions with full explanations on every answer.
Start practicing
Proactive Threat Detection — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are configuring an EDR tool to detect potential credential dumping. Which specific behavioral indicator is most effective at identifying an attacker attempting to access the LSASS process memory?
2While hunting for persistence mechanisms, you observe a suspicious scheduled task. Which detail in the task definition is the most critical indicator of a malicious actor rather than a legitimate software update?
3An organization uses the Diamond Model for threat intelligence. Which component of the model should an analyst prioritize to identify the infrastructure an adversary uses to communicate with compromised internal hosts?
4During an investigation of an incident, an analyst identifies a beaconing pattern in network logs. Which statistical analysis method is the most reliable for distinguishing this beaconing from normal, high-volume user traffic?
5During a threat hunting exercise, an analyst discovers a suspicious PowerShell execution pattern using encoded commands. Which technique should the analyst employ next to determine if the activity is malicious or legitimate system administration?
6A SOC analyst is tuning IDS signatures to reduce false positives while maintaining visibility. Which approach best balances detection efficacy with analyst workload?
7An organization is implementing a proactive detection strategy using the MITRE ATT&CK framework. Which phase of the implementation should the SOC prioritize to maximize detection coverage against common enterprise threats?
8A SOC analyst is integrating a new STIX/TAXII feed into a SIEM. Which configuration setting is mandatory to ensure the automated ingestion of threat indicators correctly maps to the internal incident response workflow?
9An organization has a SIEM and is struggling with 'alert fatigue.' What proactive measure should the SOC manager implement to improve the Signal-to-Noise ratio?
10You are designing a threat hunting hypothesis regarding an adversary using PowerShell for fileless execution. Which source of evidence provides the best visibility into the commands being executed?
11An analyst is tasked with monitoring for 'Living off the Land' (LotL) attacks. Which of the following built-in Windows utilities, if used by a non-administrative user, warrants immediate investigation?
12A SOC analyst is auditing the environment for unauthorized lateral movement. Which TWO log sources are most critical for detecting remote access techniques like RDP or SMB exploitation?
13When integrating threat intelligence into your SIEM, which THREE activities should be performed to ensure the data is actionable?
14In the context of proactive detection, which TWO of the following are effective methods for identifying 'Low and Slow' exfiltration attempts?
15Which THREE actions should be taken after an indicator of compromise (IOC) is identified to ensure it is effectively used in a proactive detection program?
16You are conducting a threat hunt for persistence. Which THREE locations in the Windows Registry should you include in your hunt as common targets for persistence?
The Proactive Threat Detection domain covers the key concepts tested in this area of the 312-39 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-39 domains — no account required.
The Courseiva 312-39 question bank contains 16 questions in the Proactive Threat Detection domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Proactive Threat Detection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included