312-39 · domain
Proactive Threat Detection
Practise Certified SOC Analyst (312-39) Proactive Threat Detection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Proactive Threat Detection questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Proactive Threat Detection
Proactive Threat Detection questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Proactive Threat Detection exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Proactive Threat Detection questions (16)
Click any question to see the full explanation, or start a practice session above.
An organization uses the Diamond Model for threat intelligence. Which component of the model should an analyst prioritize to identify the infrastructure an adversary uses to communicate with compromised internal hosts?
Easy2A SOC analyst is tuning IDS signatures to reduce false positives while maintaining visibility. Which approach best balances detection efficacy with analyst workload?
Medium3An organization is implementing a proactive detection strategy using the MITRE ATT&CK framework. Which phase of the implementation should the SOC prioritize to maximize detection coverage against common enterprise threats?
Medium4An analyst is tasked with monitoring for 'Living off the Land' (LotL) attacks. Which of the following built-in Windows utilities, if used by a non-administrative user, warrants immediate investigation?
Easy5In the context of proactive detection, which TWO of the following are effective methods for identifying 'Low and Slow' exfiltration attempts?
Hard6While hunting for persistence mechanisms, you observe a suspicious scheduled task. Which detail in the task definition is the most critical indicator of a malicious actor rather than a legitimate software update?
Hard7A SOC analyst is integrating a new STIX/TAXII feed into a SIEM. Which configuration setting is mandatory to ensure the automated ingestion of threat indicators correctly maps to the internal incident response workflow?
Easy8Which THREE actions should be taken after an indicator of compromise (IOC) is identified to ensure it is effectively used in a proactive detection program?
Medium9During a threat hunting exercise, an analyst discovers a suspicious PowerShell execution pattern using encoded commands. Which technique should the analyst employ next to determine if the activity is malicious or legitimate system administration?
Medium10You are configuring an EDR tool to detect potential credential dumping. Which specific behavioral indicator is most effective at identifying an attacker attempting to access the LSASS process memory?
Hard11An organization has a SIEM and is struggling with 'alert fatigue.' What proactive measure should the SOC manager implement to improve the Signal-to-Noise ratio?
Medium12You are designing a threat hunting hypothesis regarding an adversary using PowerShell for fileless execution. Which source of evidence provides the best visibility into the commands being executed?
Hard13You are conducting a threat hunt for persistence. Which THREE locations in the Windows Registry should you include in your hunt as common targets for persistence?
Hard14A SOC analyst is auditing the environment for unauthorized lateral movement. Which TWO log sources are most critical for detecting remote access techniques like RDP or SMB exploitation?
Medium15When integrating threat intelligence into your SIEM, which THREE activities should be performed to ensure the data is actionable?
Medium16During an investigation of an incident, an analyst identifies a beaconing pattern in network logs. Which statistical analysis method is the most reliable for distinguishing this beaconing from normal, high-volume user traffic?
HardOther domains
All 312-39 exam domains
Frequently asked questions
- What does the Proactive Threat Detection domain cover on the 312-39 exam?
- Proactive Threat Detection questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 16 Proactive Threat Detection questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Proactive Threat Detection questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.