Eccouncil

312-39 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 83-question bank.

Provider
Eccouncil
Question bank
83
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 312-39, a certification listed under Eccouncil. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Eccouncil. The certification credential is issued by Eccouncil, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Bonney's system has been compromised by a gruesome malware. What is the primary step that is advisable to Bonney in order to contain the malware incident from spreading?

    Choose one answer.

    • Complaint to police in a formal way regarding the incident
    • Turn off the infected machine
    • Leave it to the network administrators to handle
    • Call the legal department in the organization and inform about the incident
  2. Question 2 · 1

    The Syslog message severity levels are labelled from level 0 to level 7. What does level 0 indicate?

    Choose one answer.

    • Alert
    • Notification
    • Emergency
    • Debugging
  3. Question 3 · 1

    Which of the following attack can be eradicated by converting all non-alphanumeric characters to HTML character entities before displaying the user input in search engines and forums?

    Choose one answer.

    • Broken Access Control Attacks
    • Web Services Attacks
    • XSS Attacks
    • Session Management Attacks
  4. Question 4 · 1

    Where will you find the reputation IP database, if you want to monitor traffic from known bad IP reputation using OSSIM SIEM?

    Choose one answer.

    • /etc/ossim/reputation
    • /etc/ossim/siem/server/reputation/data
    • /etc/siem/ossim/server/reputation.data
    • /etc/ossim/server/reputation.data
  5. Question 5 · 1

    According to the Risk Matrix table, what will be the risk level when the probability of an attack is very low and the impact of that attack is major?

    Choose one answer.

    • High
    • Extreme
    • Low
    • Medium
  6. Question 6 · 1

    Which of the following command is used to view iptables logs on Ubuntu and Debian distributions?

    Choose one answer.

    • $ tailf /var/log/sys/kern.log
    • $ tailf /var/log/kern.log
    • # tailf /var/log/messages
    • # tailf /var/log/sys/messages
  7. Question 7 · 1

    Which of the following technique involves scanning the headers of IP packets leaving a network to make sure that the unauthorized or malicious traffic never leaves the internal network?

    Choose one answer.

    • Egress Filtering
    • Throttling
    • Rate Limiting
    • Ingress Filtering
  8. Question 8 · 1

    Which of the following formula is used to calculate the EPS of the organization?

    Choose one answer.

    • EPS = average number of correlated events / time in seconds
    • EPS = number of normalized events / time in seconds
    • EPS = number of security events / time in seconds
    • EPS = number of correlated events / time in seconds
  9. Question 9 · 1

    Juliea a SOC analyst, while monitoring logs, noticed large TXT, NULL payloads. What does this indicate?

    Choose one answer.

    • Concurrent VPN Connections Attempt
    • DNS Exfiltration Attempt
    • Covering Tracks Attempt
    • DHCP Starvation Attempt
  10. Question 10 · 1

    An organization is implementing and deploying the SIEM with following capabilities. What kind of SIEM deployment architecture the organization is planning to implement?

    Choose one answer.

    Question illustration 1
    • Cloud, MSSP Managed
    • Self-hosted, Jointly Managed
    • Self-hosted, Self-Managed
    • Self-hosted, MSSP Managed
  11. Question 11 · 1

    What is the process of monitoring and capturing all data packets passing through a given network using different tools?

    Choose one answer.

    • Network Scanning
    • DNS Footprinting
    • Network Sniffing
    • Port Scanning
  12. Question 12 · 1

    Which of the following is a report writing tool that will help incident handlers to generate efficient reports on detected incidents during incident response process?

    Choose one answer.

    • threat_note
    • MagicTree
    • IntelMQ
    • Malstrom
  13. Question 13 · 1

    According to the forensics investigation process, what is the next step carried out right after collecting the evidence?

    Choose one answer.

    • Create a Chain of Custody Document
    • Send it to the nearby police station
    • Set a Forensic lab
    • Call Organizational Disciplinary Team
  14. Question 14 · 1

    Which of the following Windows features is used to enable Security Auditing in Windows?

    Choose one answer.

    • Bitlocker
    • Windows Firewall
    • Local Group Policy Editor
    • Windows Defender
  15. Question 15 · 1

    Which of the following attack can be eradicated by filtering improper XML syntax?

    Choose one answer.

    • CAPTCHA Attacks
    • SQL Injection Attacks
    • Insufficient Logging and Monitoring Attacks
    • Web Services Attacks

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free