Sample questions
Certified SOC Analyst (312-39) practice questions
During a forensic analysis, you find a 'shimcache' entry indicating an executable ran from a volume that no longer exists. What does this suggest?
In a Windows environment, which artifact would provide the best evidence of 'Lateral Movement' using Pass-the-Hash?
Which of the following describes the 'Reconnaissance' phase in the Cyber Kill Chain?
Cyber Threats Iocs And Attack MethodologymediumSee the answer and why each option is right or wrong →An analyst notices a spike in outbound traffic to a known sinkhole IP address. What does this indicate?
A SOC analyst is reviewing logs in a SIEM and notices multiple failed login attempts followed by a successful one from an unknown IP. Which specific IoC category does this activity…
During a suspected breach, you identify a rogue process running on a Linux server. Which command identifies the network socket associated with this process?
You want to implement log integrity monitoring to ensure that logs are not tampered with after they are written. Which method is most robust?
You are tracking a threat actor who uses 'Living off the Land' (LotL) techniques. Which of the following commands is a classic indicator of this methodology?
Cyber Threats Iocs And Attack MethodologymediumSee the answer and why each option is right or wrong →Which THREE of the following are commonly monitored artifacts for detecting 'Persistence' mechanisms?
A system administrator reports high CPU usage on a server. Upon checking task manager, you find 'svchost.exe' running from a temp folder. What is the most immediate action?
Which TWO of the following are considered indicators of a 'Data Exfiltration' attempt?
Cyber Threats Iocs And Attack MethodologymediumSee the answer and why each option is right or wrong →Which component of a SIEM is responsible for identifying patterns in real-time?
You are analyzing a packet capture (PCAP) and find a beaconing pattern with a consistent 30-second interval and jitter of 5%. Which detection strategy is most effective for this Io…
You are configuring a SIEM alert and need to ensure it only triggers during business hours. Where is this configuration typically applied?
A SIEM alert indicates multiple failed logins followed by a successful login from a new IP in Splunk Enterprise Security. As a first responder, which dashboard should you navigate…
A SOC analyst is analyzing a suspected PowerShell-based attack. Which Windows log event ID is primarily used to log executed PowerShell command blocks?
Forensic Investigation And Malware AnalysiseasySee the answer and why each option is right or wrong →A SOC analyst is analyzing a suspicious email attachment. The analyst wants to extract URLs and embedded files without detonating the payload in a full sandbox. Which tool is recom…
Forensic Investigation And Malware AnalysismediumSee the answer and why each option is right or wrong →In ArcSight, a correlation rule is failing to trigger despite matching event patterns. You verify the filter logic is correct. What is the most likely cause?
You are managing a SIEM and notice a massive spike in 'false positive' alerts originating from a legacy vulnerability scanner. What is the best practice for tuning these alerts wit…
You are remediating a compromised web server. After identifying the web shell, what is the next step to prevent further access?
You have captured a malicious binary and are performing dynamic analysis. You observe the malware attempting to resolve a domain that you want to intercept. Which tool allows you t…
Forensic Investigation And Malware AnalysishardSee the answer and why each option is right or wrong →What is the purpose of 'Dashboards' in a SIEM?
You are designing a rule in a SIEM to detect brute force attacks. What is the most important factor when choosing the time window for the rule?
You need to verify if an executable is malicious. Which site is most effective for checking the hash against multiple antivirus engines?