312-39 · domain
Cyber Threats Iocs And Attack Methodology
Practise Certified SOC Analyst (312-39) Cyber Threats Iocs And Attack Methodology practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Cyber Threats Iocs And Attack Methodology questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Cyber Threats Iocs And Attack Methodology
Cyber Threats Iocs And Attack Methodology questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Cyber Threats Iocs And Attack Methodology exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Cyber Threats Iocs And Attack Methodology questions (16)
Click any question to see the full explanation, or start a practice session above.
A system administrator reports high CPU usage on a server. Upon checking task manager, you find 'svchost.exe' running from a temp folder. What is the most immediate action?
Easy2You are analyzing a packet capture (PCAP) and find a beaconing pattern with a consistent 30-second interval and jitter of 5%. Which detection strategy is most effective for this IoC?
Hard3You are investigating an incident involving a malicious macro embedded in an Excel document. Which Windows process is typically the 'parent' of the malicious payload execution?
Hard4You are tracking a threat actor who uses 'Living off the Land' (LotL) techniques. Which of the following commands is a classic indicator of this methodology?
Medium5A user complains that their browser homepage has changed. Upon inspection, you find a new, unsigned extension installed. Which attack methodology is this?
Medium6Which THREE of the following are characteristics of 'Advanced Persistent Threat' (APT) attack methodologies?
Hard7Which of the following is considered a 'Network-based' IoC?
Easy8Which TWO of the following are primary goals of the 'Command and Control' (C2) phase?
Medium9In a Windows environment, which artifact would provide the best evidence of 'Lateral Movement' using Pass-the-Hash?
Hard10Which TWO of the following are valid examples of 'Host-based' Indicators of Compromise?
Easy11Which THREE of the following are commonly monitored artifacts for detecting 'Persistence' mechanisms?
Hard12An analyst notices a spike in outbound traffic to a known sinkhole IP address. What does this indicate?
Easy13During a forensic analysis, you find a 'shimcache' entry indicating an executable ran from a volume that no longer exists. What does this suggest?
Hard14A SOC analyst is reviewing logs in a SIEM and notices multiple failed login attempts followed by a successful one from an unknown IP. Which specific IoC category does this activity represent?
Easy15Which of the following describes the 'Reconnaissance' phase in the Cyber Kill Chain?
Medium16Which TWO of the following are considered indicators of a 'Data Exfiltration' attempt?
MediumOther domains
All 312-39 exam domains
Frequently asked questions
- What does the Cyber Threats Iocs And Attack Methodology domain cover on the 312-39 exam?
- Cyber Threats Iocs And Attack Methodology questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 16 Cyber Threats Iocs And Attack Methodology questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cyber Threats Iocs And Attack Methodology questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.