312-39 · domain
Incident Detection And Triage
Practise Certified SOC Analyst (312-39) Incident Detection And Triage practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Incident Detection And Triage questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Incident Detection And Triage
Incident Detection And Triage questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Incident Detection And Triage exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Incident Detection And Triage questions (57)
Click any question to see the full explanation, or start a practice session above.
In a SIEM, what is the role of a 'Parser'?
Hard2You are investigating a SIEM alert and identify a false positive caused by a system administrator's legitimate activity. How should you document this?
Medium3You are configuring a SIEM and need to import a list of malicious IPs. What is the correct feature to use?
Hard4You are writing a SIEM query to detect unauthorized access. The query is too slow. What can you do to optimize it?
Hard5Which THREE of the following are common attributes used to prioritize security alerts during the triage process?
Medium6An analyst receives an alert for 'Possible SQL Injection'. The payload contains harmless strings. How should the analyst proceed?
Medium7When designing correlation rules for an organization, which TWO of the following practices are recommended to minimize false positives?
Hard8You are configuring a correlation rule in IBM QRadar to detect brute-force attacks. You need to ensure that the rule only triggers when a user fails to authenticate five times within a 60-second window across any three distinct source IP addresses. Which building block or configuration approach is most efficient?
Medium9A SOC analyst is reviewing alerts in Microsoft Sentinel. They want to filter the 'SecurityAlert' table to only show alerts with a 'High' severity that originated from a specific resource provider. Which KQL operator should be used?
Easy10When tuning a correlation rule in IBM QRadar, what is the role of the 'Building Block'?
Hard11Which THREE of the following represent 'Contextual Data' that can enrich a SIEM alert?
Hard12Which component of a SIEM is responsible for identifying patterns in real-time?
Easy13Which THREE of the following factors should be considered when designing a new SIEM use case?
Hard14You are performing alert triage on a potential data exfiltration attempt. The SIEM shows 50GB of data transferred to a known cloud storage IP address. What is the most important next step in your triage process?
Medium15Which of the following is a key advantage of utilizing a centralized SIEM platform?
Easy16What is a 'log source' in the context of a SIEM?
Easy17What does the 'False Positive' rate of a SIEM rule indicate?
Medium18You are managing a SIEM and notice a massive spike in 'false positive' alerts originating from a legacy vulnerability scanner. What is the best practice for tuning these alerts without losing visibility into the scanner's activity?
Medium19You are investigating a SIEM alert in Splunk that indicates a potential data exfiltration. The alert uses a threshold of 500MB. How can you improve the accuracy of this alert?
Hard20You are configuring a correlation rule in Splunk Enterprise Security. An analyst reports that too many false positives are triggered for 'Multiple Failed Login Attempts'. What is the most effective way to tune this rule?
Medium21What is the purpose of 'Dashboards' in a SIEM?
Easy22An analyst is investigating an alert regarding an outbound connection to a known malicious IP. Which step should be taken first according to standard triage procedures?
Medium23Which THREE of the following are essential for effective incident response within a SIEM?
Hard24Which of the following is an example of an 'Indicator of Compromise' (IoC)?
Easy25What is the purpose of a 'Lookback Window' in a SIEM correlation rule?
Medium26You are designing a rule in a SIEM to detect brute force attacks. What is the most important factor when choosing the time window for the rule?
Hard27Which TWO of the following are valid reasons for an analyst to escalate a SIEM incident?
Medium28Which THREE of the following are common steps during the 'Alert Triage' process?
Hard29Which of these is a common SIEM data ingestion protocol?
Easy30You are tasked with tuning a SIEM rule that is triggering on legitimate internal vulnerability scanners. What is the best course of action?
Medium31Which TWO of the following are standard log types ingested into a SIEM?
Medium32When building a new SIEM use case, what is the first phase of the development lifecycle?
Medium33During alert triage, why is it important to check the 'source' of an alert?
Medium34Which TWO of the following are key components of a successful SIEM use case development process?
Medium35You receive an alert for 'Account Lockout'. You check the logs and see 10 failures in 1 second. What does this suggest?
Medium36Which TWO of the following are primary components of a SIEM architecture?
Medium37You are reviewing a SIEM alert and see a 'Successful login' from an unusual location. What is the next logical action?
Medium38A SOC analyst is tasked with reducing 'alert fatigue' by categorizing alerts based on their MITRE ATT&CK technique mapping. Which phase of the incident response lifecycle is the analyst performing?
Easy39You suspect an attacker is using a specific user account to log in from multiple geographic locations simultaneously. Which SIEM capability allows you to detect this?
Medium40In IBM QRadar, you notice that a specific log source is not contributing to offense creation. Upon checking the 'Log Activity' tab, you see events are being parsed but are not mapped to any QID. What is the next logical step?
Hard41You are designing a correlation rule in an ArcSight ESM environment. You need to aggregate events based on a 'SessionID' field, but the 'SessionID' is not explicitly parsed in the incoming CEF logs. What must you do first?
Hard42What is the purpose of normalizing logs in a SIEM?
Easy43In ArcSight, a correlation rule is failing to trigger despite matching event patterns. You verify the filter logic is correct. What is the most likely cause?
Hard44Which TWO of the following are effective methods for reducing alert volume in a SIEM?
Medium45Which of the following describes 'Event Correlation' in a SIEM?
Easy46You are reviewing a high-severity alert. Which information is critical to gather during the initial triage?
Medium47You are configuring a SIEM alert and need to ensure it only triggers during business hours. Where is this configuration typically applied?
Hard48Which THREE of the following are common challenges in SIEM correlation rule development?
Hard49You are reviewing a SIEM alert for a 'Brute Force Attack'. You notice the source IP is from a cloud provider. How should you classify this during triage?
Medium50Which SIEM feature is used to group related events into a single incident?
Medium51You are using a SIEM and notice that logs from a critical Windows server are missing. You verify the agent is running and the network is clear. What is the next step?
Hard52What is the primary function of a SIEM collector?
Easy53When configuring log ingestion for a cloud service in a SIEM, you notice high latency in alert generation. What is the most likely cause?
Hard54What is the primary benefit of 'Threat Intelligence' integration in a SIEM?
Easy55You are designing a correlation rule in Microsoft Sentinel to detect lateral movement. You decide to use KQL to join 'SecurityEvent' and 'SigninLogs'. What is the primary benefit of using a join over a union in this scenario?
Medium56Which TWO of the following are considered best practices when configuring SIEM alerts to minimize false positives?
Medium57When performing alert triage in a SIEM, which metric is most important for prioritizing incidents based on the potential business impact?
EasyOther domains
All 312-39 exam domains
Frequently asked questions
- What does the Incident Detection And Triage domain cover on the 312-39 exam?
- Incident Detection And Triage questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 57 Incident Detection And Triage questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Incident Detection And Triage questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.