Courseiva

312-39 · domain

Cyber Threats Iocs And Attack Methodology

Practise Certified SOC Analyst (312-39) Cyber Threats Iocs And Attack Methodology practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

16 questions5 easy5 medium6 hard

Focused practice

Practice Cyber Threats Iocs And Attack Methodology questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Cyber Threats Iocs And Attack Methodology

Cyber Threats Iocs And Attack Methodology questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Cyber Threats Iocs And Attack Methodology exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Cyber Threats Iocs And Attack Methodology questions (16)

Click any question to see the full explanation, or start a practice session above.

1

A system administrator reports high CPU usage on a server. Upon checking task manager, you find 'svchost.exe' running from a temp folder. What is the most immediate action?

Easy
2

You are analyzing a packet capture (PCAP) and find a beaconing pattern with a consistent 30-second interval and jitter of 5%. Which detection strategy is most effective for this IoC?

Hard
3

You are investigating an incident involving a malicious macro embedded in an Excel document. Which Windows process is typically the 'parent' of the malicious payload execution?

Hard
4

You are tracking a threat actor who uses 'Living off the Land' (LotL) techniques. Which of the following commands is a classic indicator of this methodology?

Medium
5

A user complains that their browser homepage has changed. Upon inspection, you find a new, unsigned extension installed. Which attack methodology is this?

Medium
6

Which THREE of the following are characteristics of 'Advanced Persistent Threat' (APT) attack methodologies?

Hard
7

Which of the following is considered a 'Network-based' IoC?

Easy
8

Which TWO of the following are primary goals of the 'Command and Control' (C2) phase?

Medium
9

In a Windows environment, which artifact would provide the best evidence of 'Lateral Movement' using Pass-the-Hash?

Hard
10

Which TWO of the following are valid examples of 'Host-based' Indicators of Compromise?

Easy
11

Which THREE of the following are commonly monitored artifacts for detecting 'Persistence' mechanisms?

Hard
12

An analyst notices a spike in outbound traffic to a known sinkhole IP address. What does this indicate?

Easy
13

During a forensic analysis, you find a 'shimcache' entry indicating an executable ran from a volume that no longer exists. What does this suggest?

Hard
14

A SOC analyst is reviewing logs in a SIEM and notices multiple failed login attempts followed by a successful one from an unknown IP. Which specific IoC category does this activity represent?

Easy
15

Which of the following describes the 'Reconnaissance' phase in the Cyber Kill Chain?

Medium
16

Which TWO of the following are considered indicators of a 'Data Exfiltration' attempt?

Medium

Frequently asked questions

What does the Cyber Threats Iocs And Attack Methodology domain cover on the 312-39 exam?
Cyber Threats Iocs And Attack Methodology questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 16 Cyber Threats Iocs And Attack Methodology questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cyber Threats Iocs And Attack Methodology questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-csa ECCOUNCIL-CSA cyber threats iocs and attack methodology Practice Questions