Courseiva

312-39 · topic practice

Incident Response practice questions

Practise Certified SOC Analyst (312-39) Incident Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Incident Response

What the exam tests

What to know about Incident Response

Incident Response questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Incident Response exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Incident Response questions

20 questions · select your answer, then reveal the explanation

In an IR scenario involving a compromised Microsoft 365 account, which command in the Security & Compliance PowerShell module is used to force sign-out of all active sessions?

A SIEM alert indicates multiple failed logins followed by a successful login from a new IP in Splunk Enterprise Security. As a first responder, which dashboard should you navigate to in order to verify the MITRE ATT&CK mapping of this behavior?

While using ServiceNow Security Incident Response (SIR), you need to escalate a ticket. What is the standard process to ensure the security manager receives notification?

During incident triage, you realize an alert is a False Positive. What is the most appropriate action to take within the SIEM ticketing system?

You are triaging an alert in CrowdStrike Falcon. An endpoint shows a 'Suspicious File' detection. To verify the process tree and identify the parent process, which view do you use?

You are managing a containment procedure for an external C2 callback. Which firewall rule configuration is most effective for immediate containment?

A suspicious PowerShell script is found on an endpoint. Which tool would you use to perform volatile memory analysis to identify if the script injected malicious code?

During a suspected malware incident, a SOC analyst needs to isolate an infected workstation using Microsoft Defender for Endpoint. Which specific action should the analyst select within the Device inventory dashboard?

You are using an EDR to hunt for persistent scheduled tasks. Which artifact should you analyze to see tasks created within the last 24 hours?

What is the primary purpose of a 'War Room' during a major incident?

Question 11mediummultiple choice
Read the full Incident Response explanation →

You need to export a PCAP for a suspicious network flow. Using Wireshark, which filter would you use to isolate traffic from a specific suspicious source IP 192.168.1.50?

When dealing with a ransomware incident, why should you prioritize disconnecting the host from the network over immediate rebooting?

During an investigation, you need to perform a live acquisition of a suspect's system memory using FTK Imager. What is the correct order of operations to maintain integrity?

Which document should you reference first to determine the communication path during a high-severity security incident?

In the NIST Incident Response lifecycle, which phase involves the identification of the incident type and scope?

Question 16mediummultiple choice
Read the full Incident Response explanation →

An analyst is reviewing logs in Splunk to investigate a potential exfiltration event. Which field should the analyst focus on to identify the volume of data sent to an external IP?

You are remediating a compromised web server. After identifying the web shell, what is the next step to prevent further access?

In the context of the MITRE ATT&CK framework, what is the primary goal of the 'Command and Control' tactic?

Question 19mediummultiple choice
Read the full Incident Response explanation →

You are performing triage for an alert involving unauthorized access to an S3 bucket. Which service would you consult to review the API calls made to that bucket?

While analyzing an incident involving a malicious domain, you need to determine when the domain was registered. Which database should you query?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Incident Response sessions

Start a Incident Response only practice session

Every question in these sessions is drawn from the Incident Response domain — nothing else.

Related practice questions

Related 312-39 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 312-39 exam test about Incident Response?
Incident Response questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Incident Response questions in a focused session?
Yes — the session launcher on this page draws every question from the Incident Response domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 312-39 topics?
Use the topic links above to move to related areas, or go back to the 312-39 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 312-39 exam covers. They are not copied from any real exam or dump site.