Practice 312-39 SOC For Cloud Environments questions with full explanations on every answer.
Start practicing
SOC For Cloud Environments — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
In Azure, you suspect a compromised VM is being used for cryptocurrency mining. You want to see process-level execution details on that VM. Which tool should you use?
2You are configuring AWS GuardDuty to improve threat detection. You need to ensure it monitors for unusual S3 bucket access. Which data source must be enabled for this?
3You are managing security for GCP. You need to detect if a service account has been created with excessive permissions. Which Google Cloud tool provides this insight?
4Your organization uses Google Cloud Platform. You need to identify which service provides VPC flow logs to monitor network traffic patterns between instances. Which service is used?
5In Azure, you have detected a suspicious VM login. You need to investigate the sign-in patterns, including geographic location and device risk level. Where in the Azure portal should you look?
6You are performing a cloud-native incident response in AWS. You need to isolate a compromised EC2 instance without deleting the volume. What is the standard process?
7Which Azure feature allows you to automatically enforce security settings on your resources to prevent unauthorized changes?
8You are investigating an unauthorized login to an AWS IAM role. You need to determine the specific API call that was made and the source IP address. Which AWS service should you query?
9Which AWS service is specifically designed to act as a centralized dashboard for finding security-related misconfigurations across your entire organization?
10Which THREE of the following are benefits of using a SIEM integrated with Cloud native logs?
11You notice an unusual amount of outbound traffic from an Azure VM to a known malicious IP. What is the most effective way to block this traffic immediately at the network level?
12A SOC analyst is using GCP and sees an alert regarding 'exfiltration of data' from a Cloud Storage bucket. Which tool should be analyzed to identify the specific file names accessed during the event?
13Which TWO settings should you prioritize when configuring AWS CloudTrail for a robust security audit trail?
14Which TWO of the following are primary components of a cloud-native incident response plan?
15Which THREE of the following are common indicators of a cloud account compromise that should be monitored in your SOC?
16Which TWO actions should be taken when you find a rogue VM in your GCP environment?
The SOC For Cloud Environments domain covers the key concepts tested in this area of the 312-39 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-39 domains — no account required.
The Courseiva 312-39 question bank contains 16 questions in the SOC For Cloud Environments domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the SOC For Cloud Environments domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included