Courseiva

312-39 · domain

Incident Response

Practise Certified SOC Analyst (312-39) Incident Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

49 questions16 easy18 medium15 hard

Focused practice

Practice Incident Response questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Incident Response

Incident Response questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Incident Response exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Incident Response questions (49)

Click any question to see the full explanation, or start a practice session above.

1

Which THREE actions are part of the 'Recovery' phase?

Medium
2

A suspicious PowerShell script is found on an endpoint. Which tool would you use to perform volatile memory analysis to identify if the script injected malicious code?

Medium
3

A SIEM alert indicates multiple failed logins followed by a successful login from a new IP in Splunk Enterprise Security. As a first responder, which dashboard should you navigate to in order to verify the MITRE ATT&CK mapping of this behavior?

Hard
4

Which THREE tools are typically used for forensic memory analysis?

Medium
5

You are analyzing an alert for a suspicious PowerShell command. Which logging setting must be enabled on Windows endpoints to capture the full command-line arguments?

Medium
6

You are managing a containment procedure for an external C2 callback. Which firewall rule configuration is most effective for immediate containment?

Hard
7

You notice an anomaly in your DNS traffic. Which type of DNS record is commonly associated with DNS tunneling for command and control?

Hard
8

What is the primary goal of the 'Eradication' phase in incident response?

Easy
9

During incident triage, you realize an alert is a False Positive. What is the most appropriate action to take within the SIEM ticketing system?

Easy
10

Which TWO steps are part of the 'Preparation' phase of the incident response process?

Easy
11

During a suspected malware incident, a SOC analyst needs to isolate an infected workstation using Microsoft Defender for Endpoint. Which specific action should the analyst select within the Device inventory dashboard?

Medium
12

What is the primary purpose of a 'War Room' during a major incident?

Easy
13

What is the main objective of the 'Post-Incident Activity' phase?

Easy
14

Which document is essential for recording every action taken during an incident for legal and audit purposes?

Easy
15

You are remediating a compromised web server. After identifying the web shell, what is the next step to prevent further access?

Hard
16

You are investigating a data exfiltration incident. Which protocol's logs would most likely show large volumes of data being moved to a cloud storage provider?

Hard
17

A ticket is assigned to you with high priority. What is the first thing you should do?

Easy
18

Which TWO types of evidence should be collected during the identification phase of an incident?

Easy
19

When an analyst suspects that a malicious user is using a VPN to hide their source IP, which technique is most helpful for attribution?

Medium
20

While using ServiceNow Security Incident Response (SIR), you need to escalate a ticket. What is the standard process to ensure the security manager receives notification?

Easy
21

Which TWO methods are commonly used to achieve persistence on a Windows host?

Medium
22

You are performing triage for an alert involving unauthorized access to an S3 bucket. Which service would you consult to review the API calls made to that bucket?

Medium
23

Which TWO indicators should an analyst watch for in a potential phishing campaign?

Easy
24

Which THREE items should be included in a standard incident containment report?

Hard
25

Which THREE factors should be considered when determining the severity level of an incident?

Hard
26

During a phishing investigation, you receive a suspicious link. Which safety measure should you use to analyze the link?

Medium
27

Which TWO types of logs are most useful for detecting lateral movement?

Medium
28

You are auditing user access logs for a potential privilege escalation. What indicates that a user has successfully used 'runas' to switch context?

Hard
29

In the context of the MITRE ATT&CK framework, what is the primary goal of the 'Command and Control' tactic?

Easy
30

When dealing with a ransomware incident, why should you prioritize disconnecting the host from the network over immediate rebooting?

Hard
31

Which THREE factors contribute to 'dwell time' in a security incident?

Medium
32

You need to export a PCAP for a suspicious network flow. Using Wireshark, which filter would you use to isolate traffic from a specific suspicious source IP 192.168.1.50?

Medium
33

What is the primary function of an IOC (Indicator of Compromise) in an incident?

Easy
34

Which TWO actions should be taken immediately upon identifying an active malware infection on a workstation?

Easy
35

Which TWO pieces of information are critical to include in an initial incident ticket?

Medium
36

In the NIST Incident Response lifecycle, which phase involves the identification of the incident type and scope?

Easy
37

Which TWO items are part of the 'Lessons Learned' process?

Easy
38

You are using an EDR to hunt for persistent scheduled tasks. Which artifact should you analyze to see tasks created within the last 24 hours?

Medium
39

You are investigating a suspicious login. Which attribute in the Azure AD sign-in logs helps determine if the user successfully authenticated using MFA?

Medium
40

You are triaging an alert in CrowdStrike Falcon. An endpoint shows a 'Suspicious File' detection. To verify the process tree and identify the parent process, which view do you use?

Medium
41

During a suspected lateral movement incident, you observe successful SMB sessions between two workstations. Which tool in Windows can be used to view these active sessions?

Hard
42

Which document should you reference first to determine the communication path during a high-severity security incident?

Easy
43

An analyst is reviewing logs in Splunk to investigate a potential exfiltration event. Which field should the analyst focus on to identify the volume of data sent to an external IP?

Medium
44

During an investigation, you need to perform a live acquisition of a suspect's system memory using FTK Imager. What is the correct order of operations to maintain integrity?

Hard
45

While analyzing an incident involving a malicious domain, you need to determine when the domain was registered. Which database should you query?

Hard
46

During a suspected breach, you identify a rogue process running on a Linux server. Which command identifies the network socket associated with this process?

Hard
47

Which THREE actions are appropriate during the eradication phase of a malware incident?

Hard
48

You need to verify if an executable is malicious. Which site is most effective for checking the hash against multiple antivirus engines?

Medium
49

Which THREE elements are essential in an incident notification email to senior management?

Hard

Frequently asked questions

What does the Incident Response domain cover on the 312-39 exam?
Incident Response questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 49 Incident Response questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Incident Response questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-csa ECCOUNCIL-CSA incident response Practice Questions