312-39 Sample Questions & Answers
SIEM architecture, deployment, and use-case development take the top share, framed by SOC fundamentals and tools, the threat landscape and indicators of compromise, log correlation, threat-intelligence hunting, and the incident response process.
Launch the full 312-39 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Understanding Cyber Threats, IoCs, and Attack Methodology · Cyber Kill Chain
True or False: In the Cyber Kill Chain model, the 'Installation' phase always occurs before the 'Command and Control' phase.
Show answer & explanation
Correct answer: A
True. According to the Lockheed Martin Cyber Kill Chain model, the 'Installation' phase, where malware establishes persistence on the victim's system, precedes the 'Command and Control' (C2) phase. During the C2 phase, the installed malware 'calls home' to the attacker's infrastructure to receive instructions. Persistence must be established first to ensure the C2 channel can be maintained.
- Question 2Beginner
Incident Response · Incident Response Process
An organization's incident response policy mandates that after containing a malware outbreak on several workstations, the next step is 'Eradication'. Which of the following activities is a core part of the Eradication phase?
Show answer & explanation
Correct answer: D
The Eradication phase of the incident response lifecycle focuses on completely removing the threat from the environment. This includes deleting the malware, removing persistence mechanisms (like registry keys or scheduled tasks), and eliminating any other tools or backdoors left by the attacker. Isolation is part of Containment, restoring data is part of Recovery, and lessons learned is the final post-incident phase.
- Question 3Intermediate
Incident Detection with Security Information and Event Management (SIEM) · SIEM Querying
A SOC analyst needs to write a query in a Splunk-based SIEM to find all successful RDP login events (EventCode=4624) from IP addresses outside of the company's designated country code (US). Which of the following Splunk queries is the best approach to accomplish this?
Show answer & explanation
Correct answer: B
This query correctly filters for the specific Windows event for a successful logon (EventCode=4624), then uses the
iplocationcommand to enrich the events with geographic data based on the source IP address (src_ip). Finally, it uses asearchcommand to filter those enriched events to show only those where theCountryfield is not equal to 'US'. The other options are incorrect or less efficient. - Question 4Intermediate
Incidents, Events, and Logging · Log Management and Retention
A financial services firm is required to comply with a regulation that mandates a log retention period of seven years for all authentication and transaction logs. The firm's current SIEM solution stores all data in 'hot' storage for fast querying, which is becoming prohibitively expensive for long-term retention. What is the most appropriate architectural solution for the SOC to propose?
Show answer & explanation
Correct answer: B
A data tiering strategy is the industry-standard solution for balancing performance and cost in long-term log retention. Logs are kept in expensive, high-performance 'hot' storage for a short period (e.g., 30-90 days) for immediate analysis. After that, they are moved to cheaper, slower 'warm' or 'cold' storage (like AWS S3 Glacier or an on-premise NAS). This meets the compliance requirement for retention without the exorbitant cost of keeping all data in hot storage. Data can still be re-ingested or queried from cold storage if needed for a forensic investigation, albeit more slowly.
- Question 5Beginner
Understanding Cyber Threats, IoCs, and Attack Methodology · Attack Methodology
A SOC analyst is investigating an alert indicating that a sensitive file was accessed on a file server from a user account that has been dormant for over a year. Which attack methodology concept does this activity MOST closely align with?
Show answer & explanation
Correct answer: D
This scenario describes a specific Tactic, Technique, and Procedure (TTP). The tactic is 'Persistence' or 'Defense Evasion', the technique is 'Valid Accounts', and the specific procedure is the use of a dormant account to access resources. An IoC is the evidence itself (e.g., the log entry), not the methodology. Zero-day and DoS are types of attacks, but the concept of using a dormant account is a classic TTP employed by attackers to blend in and avoid detection.
- Question 6Beginner
Security Operations and Management · SOC Fundamentals
A SOC uses a 'follow-the-sun' model with teams located in North America, Europe, and Asia. What is the primary operational advantage of this SOC model?
Show answer & explanation
Correct answer: B
The primary advantage of a 'follow-the-sun' model is its ability to provide continuous, 24/7 security monitoring by handing off operations between geographically distributed teams. As one team's business day ends, another team's day begins, ensuring that alerts are always handled by an active, alert team working regular business hours. This avoids the analyst burnout and potential for error associated with overnight shifts.
- Question 7Intermediate
Understanding Cyber Threats, IoCs, and Attack Methodology · Attack Types and Methodologies
While analyzing web application logs, a SOC analyst discovers the following URL request:
https://e-corp.com/getUser?id=123; cat /etc/passwd. This is an example of what type of attack?Show answer & explanation
Correct answer: C
This is a classic example of a Command Injection attack. The attacker is using a semicolon (
;) to terminate the expected parameter (id=123) and inject a new, arbitrary operating system command (cat /etc/passwd). If the backend application is vulnerable, it will execute this command on the server, potentially revealing the contents of the password file. SQL injection involves database commands, while XSS involves injecting scripts into a web page to be executed by a user's browser. - Question 8Intermediate
Incident Response · Incident Response Process
A hospital's SOC has deployed a new User and Entity Behavior Analytics (UEBA) module for their SIEM. The UEBA system flags an alert for a doctor's account that accessed 500 patient records between 2 AM and 3 AM. This access pattern is highly anomalous compared to the doctor's normal daytime activity. Which stage of incident response is the SOC currently in?
Show answer & explanation
Correct answer: B
The SOC is in the Detection and Analysis phase. The UEBA system has detected a potential incident based on anomalous behavior, and the SOC's role is now to analyze this alert to determine if it is a true positive (e.g., a compromised account) or a false positive (e.g., the doctor was legitimately working late). This analysis must happen before moving to Containment. Preparation involves getting tools and processes ready, which has already been done.
- Question 9Beginner
Incidents, Events, and Logging · Log Management Fundamentals
True or False: A major benefit of log normalization in a SIEM is that it allows a single correlation rule to apply to logs from multiple, disparate vendor sources.
Show answer & explanation
Correct answer: A
True. Log normalization is the process of parsing logs from different sources and converting them into a common format (like the Splunk Common Information Model - CIM). For example, a Cisco firewall might log a source IP as
src_ip, while a Palo Alto firewall logs it assource_address. Normalization maps both fields to a common field, likesrc. This allows a single correlation rule, such assearch src=1.2.3.4, to work on data from both vendors, dramatically simplifying rule creation and management. - Question 10Intermediate
Incident Detection with SIEM · Network-based Incident Detection
A SOC analyst receives an alert for a potential data exfiltration event. The SIEM shows that a user workstation initiated an outbound connection to an unknown IP address on port 53, transferring an unusually large amount of data (25 MB). Legitimate DNS queries are typically very small. This technique is known as what?
Show answer & explanation
Correct answer: C
This is a classic example of DNS Tunneling. Attackers abuse the DNS protocol to establish a command-and-control (C2) channel or exfiltrate data. Since DNS traffic (port 53) is almost always allowed through firewalls, it provides a covert channel. Large data transfers over DNS are highly anomalous and a strong indicator of this technique. A DNS amplification attack is a type of DDoS, and Fast-Flux is a technique to hide C2 servers behind a rapidly changing set of IPs.
Ready for the real thing?
The full 312-39 simulator has every exam-style question, timed mode, and instant scoring.