Courseiva

312-39 · domain

Proactive Threat Detection

Practise Certified SOC Analyst (312-39) Proactive Threat Detection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

16 questions3 easy7 medium6 hard

Focused practice

Practice Proactive Threat Detection questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Proactive Threat Detection

Proactive Threat Detection questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Proactive Threat Detection exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Proactive Threat Detection questions (16)

Click any question to see the full explanation, or start a practice session above.

1

An organization uses the Diamond Model for threat intelligence. Which component of the model should an analyst prioritize to identify the infrastructure an adversary uses to communicate with compromised internal hosts?

Easy
2

A SOC analyst is tuning IDS signatures to reduce false positives while maintaining visibility. Which approach best balances detection efficacy with analyst workload?

Medium
3

An organization is implementing a proactive detection strategy using the MITRE ATT&CK framework. Which phase of the implementation should the SOC prioritize to maximize detection coverage against common enterprise threats?

Medium
4

An analyst is tasked with monitoring for 'Living off the Land' (LotL) attacks. Which of the following built-in Windows utilities, if used by a non-administrative user, warrants immediate investigation?

Easy
5

In the context of proactive detection, which TWO of the following are effective methods for identifying 'Low and Slow' exfiltration attempts?

Hard
6

While hunting for persistence mechanisms, you observe a suspicious scheduled task. Which detail in the task definition is the most critical indicator of a malicious actor rather than a legitimate software update?

Hard
7

A SOC analyst is integrating a new STIX/TAXII feed into a SIEM. Which configuration setting is mandatory to ensure the automated ingestion of threat indicators correctly maps to the internal incident response workflow?

Easy
8

Which THREE actions should be taken after an indicator of compromise (IOC) is identified to ensure it is effectively used in a proactive detection program?

Medium
9

During a threat hunting exercise, an analyst discovers a suspicious PowerShell execution pattern using encoded commands. Which technique should the analyst employ next to determine if the activity is malicious or legitimate system administration?

Medium
10

You are configuring an EDR tool to detect potential credential dumping. Which specific behavioral indicator is most effective at identifying an attacker attempting to access the LSASS process memory?

Hard
11

An organization has a SIEM and is struggling with 'alert fatigue.' What proactive measure should the SOC manager implement to improve the Signal-to-Noise ratio?

Medium
12

You are designing a threat hunting hypothesis regarding an adversary using PowerShell for fileless execution. Which source of evidence provides the best visibility into the commands being executed?

Hard
13

You are conducting a threat hunt for persistence. Which THREE locations in the Windows Registry should you include in your hunt as common targets for persistence?

Hard
14

A SOC analyst is auditing the environment for unauthorized lateral movement. Which TWO log sources are most critical for detecting remote access techniques like RDP or SMB exploitation?

Medium
15

When integrating threat intelligence into your SIEM, which THREE activities should be performed to ensure the data is actionable?

Medium
16

During an investigation of an incident, an analyst identifies a beaconing pattern in network logs. Which statistical analysis method is the most reliable for distinguishing this beaconing from normal, high-volume user traffic?

Hard

Frequently asked questions

What does the Proactive Threat Detection domain cover on the 312-39 exam?
Proactive Threat Detection questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 16 Proactive Threat Detection questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Proactive Threat Detection questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-csa ECCOUNCIL-CSA proactive threat detection Practice Questions