Courseiva
Back to Certified SOC Analyst (312-39) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified SOC Analyst (312-39) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
312-39
exam code
EC-Council
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related 312-39 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which THREE of the following are commonly monitored artifacts for detecting 'Persistence' mechanisms?

Question 2mediummulti select
Full question →

Which TWO of the following are considered indicators of a 'Data Exfiltration' attempt?

Question 3easymulti select
Full question →

Which TWO indicators should an analyst watch for in a potential phishing campaign?

Question 4mediummulti select
Full question →

When integrating threat intelligence into your SIEM, which THREE activities should be performed to ensure the data is actionable?

Question 5hardmulti select
Full question →

In the context of proactive detection, which TWO of the following are effective methods for identifying 'Low and Slow' exfiltration attempts?

Question 6hardmulti select
Full question →

Which THREE of the following are common steps during the 'Alert Triage' process?

Question 7mediummulti select
Full question →

Which TWO of the following are key components of a successful SIEM use case development process?

Question 8hardmulti select
Full question →

When designing correlation rules for an organization, which TWO of the following practices are recommended to minimize false positives?

Question 9mediummulti select
Full question →

Which THREE of the following are common attributes used to prioritize security alerts during the triage process?

Question 10mediummulti select
Full question →

Which THREE factors contribute to 'dwell time' in a security incident?

Question 11mediummulti select
Full question →

Which TWO factors are most critical when calculating the ROI of a SOC?

Question 12hardmulti select
Full question →

Which THREE of the following are common indicators of a cloud account compromise that should be monitored in your SOC?

Question 13mediummulti select
Full question →

Which TWO settings should you prioritize when configuring AWS CloudTrail for a robust security audit trail?

Question 14easymulti select
Full question →

Which TWO of the following are valid examples of 'Host-based' Indicators of Compromise?

Question 15easymulti select
Full question →

A SOC analyst is preparing to collect digital evidence from a compromised server. Which TWO actions must be documented to maintain a proper Chain of Custody?

Question 16mediummulti select
Full question →

Which TWO of the following are primary goals of the 'Command and Control' (C2) phase?

Question 17mediummulti select
Full question →

Which TWO types of evidence are classified as 'volatile' and should be captured first during a forensic investigation?

Question 18mediummulti select
Full question →

When performing static analysis of a malicious binary, which THREE indicators should an analyst typically look for?

Question 19mediummulti select
Full question →

Which TWO of the following are considered best practices when configuring SIEM alerts to minimize false positives?

Question 20hardmulti select
Full question →

In the context of malware analysis, which TWO of the following are primary differences between static and dynamic analysis?

These 312-39 practice questions are part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style 312-39 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.