312-39 · domain
Incident Response
Practise Certified SOC Analyst (312-39) Incident Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Incident Response questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Incident Response
Incident Response questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Incident Response exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Incident Response questions (49)
Click any question to see the full explanation, or start a practice session above.
Which THREE actions are part of the 'Recovery' phase?
Medium2A suspicious PowerShell script is found on an endpoint. Which tool would you use to perform volatile memory analysis to identify if the script injected malicious code?
Medium3A SIEM alert indicates multiple failed logins followed by a successful login from a new IP in Splunk Enterprise Security. As a first responder, which dashboard should you navigate to in order to verify the MITRE ATT&CK mapping of this behavior?
Hard4Which THREE tools are typically used for forensic memory analysis?
Medium5You are analyzing an alert for a suspicious PowerShell command. Which logging setting must be enabled on Windows endpoints to capture the full command-line arguments?
Medium6You are managing a containment procedure for an external C2 callback. Which firewall rule configuration is most effective for immediate containment?
Hard7You notice an anomaly in your DNS traffic. Which type of DNS record is commonly associated with DNS tunneling for command and control?
Hard8What is the primary goal of the 'Eradication' phase in incident response?
Easy9During incident triage, you realize an alert is a False Positive. What is the most appropriate action to take within the SIEM ticketing system?
Easy10Which TWO steps are part of the 'Preparation' phase of the incident response process?
Easy11During a suspected malware incident, a SOC analyst needs to isolate an infected workstation using Microsoft Defender for Endpoint. Which specific action should the analyst select within the Device inventory dashboard?
Medium12What is the primary purpose of a 'War Room' during a major incident?
Easy13What is the main objective of the 'Post-Incident Activity' phase?
Easy14Which document is essential for recording every action taken during an incident for legal and audit purposes?
Easy15You are remediating a compromised web server. After identifying the web shell, what is the next step to prevent further access?
Hard16You are investigating a data exfiltration incident. Which protocol's logs would most likely show large volumes of data being moved to a cloud storage provider?
Hard17A ticket is assigned to you with high priority. What is the first thing you should do?
Easy18Which TWO types of evidence should be collected during the identification phase of an incident?
Easy19When an analyst suspects that a malicious user is using a VPN to hide their source IP, which technique is most helpful for attribution?
Medium20While using ServiceNow Security Incident Response (SIR), you need to escalate a ticket. What is the standard process to ensure the security manager receives notification?
Easy21Which TWO methods are commonly used to achieve persistence on a Windows host?
Medium22You are performing triage for an alert involving unauthorized access to an S3 bucket. Which service would you consult to review the API calls made to that bucket?
Medium23Which TWO indicators should an analyst watch for in a potential phishing campaign?
Easy24Which THREE items should be included in a standard incident containment report?
Hard25Which THREE factors should be considered when determining the severity level of an incident?
Hard26During a phishing investigation, you receive a suspicious link. Which safety measure should you use to analyze the link?
Medium27Which TWO types of logs are most useful for detecting lateral movement?
Medium28You are auditing user access logs for a potential privilege escalation. What indicates that a user has successfully used 'runas' to switch context?
Hard29In the context of the MITRE ATT&CK framework, what is the primary goal of the 'Command and Control' tactic?
Easy30When dealing with a ransomware incident, why should you prioritize disconnecting the host from the network over immediate rebooting?
Hard31Which THREE factors contribute to 'dwell time' in a security incident?
Medium32You need to export a PCAP for a suspicious network flow. Using Wireshark, which filter would you use to isolate traffic from a specific suspicious source IP 192.168.1.50?
Medium33What is the primary function of an IOC (Indicator of Compromise) in an incident?
Easy34Which TWO actions should be taken immediately upon identifying an active malware infection on a workstation?
Easy35Which TWO pieces of information are critical to include in an initial incident ticket?
Medium36In the NIST Incident Response lifecycle, which phase involves the identification of the incident type and scope?
Easy37Which TWO items are part of the 'Lessons Learned' process?
Easy38You are using an EDR to hunt for persistent scheduled tasks. Which artifact should you analyze to see tasks created within the last 24 hours?
Medium39You are investigating a suspicious login. Which attribute in the Azure AD sign-in logs helps determine if the user successfully authenticated using MFA?
Medium40You are triaging an alert in CrowdStrike Falcon. An endpoint shows a 'Suspicious File' detection. To verify the process tree and identify the parent process, which view do you use?
Medium41During a suspected lateral movement incident, you observe successful SMB sessions between two workstations. Which tool in Windows can be used to view these active sessions?
Hard42Which document should you reference first to determine the communication path during a high-severity security incident?
Easy43An analyst is reviewing logs in Splunk to investigate a potential exfiltration event. Which field should the analyst focus on to identify the volume of data sent to an external IP?
Medium44During an investigation, you need to perform a live acquisition of a suspect's system memory using FTK Imager. What is the correct order of operations to maintain integrity?
Hard45While analyzing an incident involving a malicious domain, you need to determine when the domain was registered. Which database should you query?
Hard46During a suspected breach, you identify a rogue process running on a Linux server. Which command identifies the network socket associated with this process?
Hard47Which THREE actions are appropriate during the eradication phase of a malware incident?
Hard48You need to verify if an executable is malicious. Which site is most effective for checking the hash against multiple antivirus engines?
Medium49Which THREE elements are essential in an incident notification email to senior management?
HardOther domains
All 312-39 exam domains
Frequently asked questions
- What does the Incident Response domain cover on the 312-39 exam?
- Incident Response questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 49 Incident Response questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Incident Response questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.