Give Push to your Success with EC-COUNCIL CSA 312-39 Exam Questions [Q16-Q36]

4.7/5 - (3 votes)

Give Push to your Success with EC-COUNCIL CSA 312-39 Exam Questions

312-39 100% Guarantee Download 312-39 Exam PDF Q&A

The Certified SOC Analyst (CSA) certification is offered by the International Council of E-Commerce Consultants (EC-Council) as a way for professionals in the cybersecurity industry to demonstrate their knowledge and skills in the area of Security Operations Centers (SOCs). Certified SOC Analyst (CSA) certification is designed for individuals who are responsible for detecting, analyzing, and responding to cybersecurity incidents within an organization.

 

Q16. Which of the following attack can be eradicated by disabling of “allow_url_fopen and allow_url_include” in the php.ini file?

 
 
 
 

Q17. In which log collection mechanism, the system or application sends log records either on the local disk or over the network.

 
 
 
 

Q18. Identify the password cracking attempt involving a precomputed dictionary of plaintext passwords and their corresponding hash values to crack the password.

 
 
 
 

Q19. Identify the HTTP status codes that represents the server error.

 
 
 
 

Q20. What is the process of monitoring and capturing all data packets passing through a given network using different tools?

 
 
 
 

Q21. Which attack works like a dictionary attack, but adds some numbers and symbols to the words from the dictionary and tries to crack the password?

 
 
 
 

Q22. John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.
Which of the following data source will he use to prepare the dashboard?

 
 
 
 

Q23. Which of the following Windows event is logged every time when a user tries to access the “Registry” key?

 
 
 
 

Q24. Jony, a security analyst, while monitoring IIS logs, identified events shown in the figure below.

What does this event log indicate?

 
 
 
 

Q25. Which of the following tool is used to recover from web application incident?

 
 
 
 

Q26. An organization wants to implement a SIEM deployment architecture. However, they have the capability to do only log collection and the rest of the SIEM functions must be managed by an MSSP.
Which SIEM deployment architecture will the organization adopt?

 
 
 
 

Q27. Which of the following is a set of standard guidelines for ongoing development, enhancement, storage, dissemination and implementation of security standards for account data protection?

 
 
 
 

Q28. Which of the following Windows event is logged every time when a user tries to access the “Registry” key?

 
 
 
 

Q29. An attacker exploits the logic validation mechanisms of an e-commerce website. He successfully purchases a product worth $100 for $10 by modifying the URL exchanged between the client and the server.
Original
URL: http://www.buyonline.com/product.aspx?profile=12
&debit=100
Modified URL: http://www.buyonline.com/product.aspx?profile=12
&debit=10
Identify the attack depicted in the above scenario.

 
 
 
 

Q30. Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry:
May 06 2018 21:27:27 asa 1: %ASA -5 – 11008: User ‘enable_15’ executed the ‘configure term’ command What does the security level in the above log indicates?

 
 
 
 

Q31. Which of the following is a Threat Intelligence Platform?

 
 
 
 

Q32. Identify the attack in which the attacker exploits a target system through publicly known but still unpatched vulnerabilities.

 
 
 
 

Q33. Identify the attack when an attacker by several trial and error can read the contents of a password file present in the restricted etc folder just by manipulating the URL in the browser as shown:
http://www.terabytes.com/process.php./../../../../etc/passwd

 
 
 
 

Q34. In which of the following incident handling and response stages, the root cause of the incident must be found from the forensic results?

 
 
 
 

Q35. Robin, a SOC engineer in a multinational company, is planning to implement a SIEM. He realized that his organization is capable of performing only Correlation, Analytics, Reporting, Retention, Alerting, and Visualization required for the SIEM implementation and has to take collection and aggregation services from a Managed Security Services Provider (MSSP).
What kind of SIEM is Robin planning to implement?

 
 
 
 

Q36. Which of the following data source will a SOC Analyst use to monitor connections to the insecure ports?

 
 
 
 

Get 312-39 Actual Free Exam Q&As to Prepare Certification: https://www.actualpdf.com/312-39_exam-dumps.html

         

Related Links: myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt www.stes.tyc.edu.tw

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter the text from the image below