Courseiva

312-39 · domain

Incident Detection And Triage

Practise Certified SOC Analyst (312-39) Incident Detection And Triage practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

57 questions13 easy26 medium18 hard

Focused practice

Practice Incident Detection And Triage questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Incident Detection And Triage

Incident Detection And Triage questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Incident Detection And Triage exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Incident Detection And Triage questions (57)

Click any question to see the full explanation, or start a practice session above.

1

In a SIEM, what is the role of a 'Parser'?

Hard
2

You are investigating a SIEM alert and identify a false positive caused by a system administrator's legitimate activity. How should you document this?

Medium
3

You are configuring a SIEM and need to import a list of malicious IPs. What is the correct feature to use?

Hard
4

You are writing a SIEM query to detect unauthorized access. The query is too slow. What can you do to optimize it?

Hard
5

Which THREE of the following are common attributes used to prioritize security alerts during the triage process?

Medium
6

An analyst receives an alert for 'Possible SQL Injection'. The payload contains harmless strings. How should the analyst proceed?

Medium
7

When designing correlation rules for an organization, which TWO of the following practices are recommended to minimize false positives?

Hard
8

You are configuring a correlation rule in IBM QRadar to detect brute-force attacks. You need to ensure that the rule only triggers when a user fails to authenticate five times within a 60-second window across any three distinct source IP addresses. Which building block or configuration approach is most efficient?

Medium
9

A SOC analyst is reviewing alerts in Microsoft Sentinel. They want to filter the 'SecurityAlert' table to only show alerts with a 'High' severity that originated from a specific resource provider. Which KQL operator should be used?

Easy
10

When tuning a correlation rule in IBM QRadar, what is the role of the 'Building Block'?

Hard
11

Which THREE of the following represent 'Contextual Data' that can enrich a SIEM alert?

Hard
12

Which component of a SIEM is responsible for identifying patterns in real-time?

Easy
13

Which THREE of the following factors should be considered when designing a new SIEM use case?

Hard
14

You are performing alert triage on a potential data exfiltration attempt. The SIEM shows 50GB of data transferred to a known cloud storage IP address. What is the most important next step in your triage process?

Medium
15

Which of the following is a key advantage of utilizing a centralized SIEM platform?

Easy
16

What is a 'log source' in the context of a SIEM?

Easy
17

What does the 'False Positive' rate of a SIEM rule indicate?

Medium
18

You are managing a SIEM and notice a massive spike in 'false positive' alerts originating from a legacy vulnerability scanner. What is the best practice for tuning these alerts without losing visibility into the scanner's activity?

Medium
19

You are investigating a SIEM alert in Splunk that indicates a potential data exfiltration. The alert uses a threshold of 500MB. How can you improve the accuracy of this alert?

Hard
20

You are configuring a correlation rule in Splunk Enterprise Security. An analyst reports that too many false positives are triggered for 'Multiple Failed Login Attempts'. What is the most effective way to tune this rule?

Medium
21

What is the purpose of 'Dashboards' in a SIEM?

Easy
22

An analyst is investigating an alert regarding an outbound connection to a known malicious IP. Which step should be taken first according to standard triage procedures?

Medium
23

Which THREE of the following are essential for effective incident response within a SIEM?

Hard
24

Which of the following is an example of an 'Indicator of Compromise' (IoC)?

Easy
25

What is the purpose of a 'Lookback Window' in a SIEM correlation rule?

Medium
26

You are designing a rule in a SIEM to detect brute force attacks. What is the most important factor when choosing the time window for the rule?

Hard
27

Which TWO of the following are valid reasons for an analyst to escalate a SIEM incident?

Medium
28

Which THREE of the following are common steps during the 'Alert Triage' process?

Hard
29

Which of these is a common SIEM data ingestion protocol?

Easy
30

You are tasked with tuning a SIEM rule that is triggering on legitimate internal vulnerability scanners. What is the best course of action?

Medium
31

Which TWO of the following are standard log types ingested into a SIEM?

Medium
32

When building a new SIEM use case, what is the first phase of the development lifecycle?

Medium
33

During alert triage, why is it important to check the 'source' of an alert?

Medium
34

Which TWO of the following are key components of a successful SIEM use case development process?

Medium
35

You receive an alert for 'Account Lockout'. You check the logs and see 10 failures in 1 second. What does this suggest?

Medium
36

Which TWO of the following are primary components of a SIEM architecture?

Medium
37

You are reviewing a SIEM alert and see a 'Successful login' from an unusual location. What is the next logical action?

Medium
38

A SOC analyst is tasked with reducing 'alert fatigue' by categorizing alerts based on their MITRE ATT&CK technique mapping. Which phase of the incident response lifecycle is the analyst performing?

Easy
39

You suspect an attacker is using a specific user account to log in from multiple geographic locations simultaneously. Which SIEM capability allows you to detect this?

Medium
40

In IBM QRadar, you notice that a specific log source is not contributing to offense creation. Upon checking the 'Log Activity' tab, you see events are being parsed but are not mapped to any QID. What is the next logical step?

Hard
41

You are designing a correlation rule in an ArcSight ESM environment. You need to aggregate events based on a 'SessionID' field, but the 'SessionID' is not explicitly parsed in the incoming CEF logs. What must you do first?

Hard
42

What is the purpose of normalizing logs in a SIEM?

Easy
43

In ArcSight, a correlation rule is failing to trigger despite matching event patterns. You verify the filter logic is correct. What is the most likely cause?

Hard
44

Which TWO of the following are effective methods for reducing alert volume in a SIEM?

Medium
45

Which of the following describes 'Event Correlation' in a SIEM?

Easy
46

You are reviewing a high-severity alert. Which information is critical to gather during the initial triage?

Medium
47

You are configuring a SIEM alert and need to ensure it only triggers during business hours. Where is this configuration typically applied?

Hard
48

Which THREE of the following are common challenges in SIEM correlation rule development?

Hard
49

You are reviewing a SIEM alert for a 'Brute Force Attack'. You notice the source IP is from a cloud provider. How should you classify this during triage?

Medium
50

Which SIEM feature is used to group related events into a single incident?

Medium
51

You are using a SIEM and notice that logs from a critical Windows server are missing. You verify the agent is running and the network is clear. What is the next step?

Hard
52

What is the primary function of a SIEM collector?

Easy
53

When configuring log ingestion for a cloud service in a SIEM, you notice high latency in alert generation. What is the most likely cause?

Hard
54

What is the primary benefit of 'Threat Intelligence' integration in a SIEM?

Easy
55

You are designing a correlation rule in Microsoft Sentinel to detect lateral movement. You decide to use KQL to join 'SecurityEvent' and 'SigninLogs'. What is the primary benefit of using a join over a union in this scenario?

Medium
56

Which TWO of the following are considered best practices when configuring SIEM alerts to minimize false positives?

Medium
57

When performing alert triage in a SIEM, which metric is most important for prioritizing incidents based on the potential business impact?

Easy

Frequently asked questions

What does the Incident Detection And Triage domain cover on the 312-39 exam?
Incident Detection And Triage questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 57 Incident Detection And Triage questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Incident Detection And Triage questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Certified SOC Analyst (312-39) Incident Detection And Triage Practice Questions