312-39 Dumps

312-39 Free Practice Test

EC-Council 312-39: Certified SOC Analyst (CSA)

QUESTION 11

Which of the following is a report writing tool that will help incident handlers to generate efficient reports on detected incidents during incident response process?

Correct Answer: C

QUESTION 12

Where will you find the reputation IP database, if you want to monitor traffic from known bad IP reputation using OSSIM SIEM?

Correct Answer: A

QUESTION 13

Which of the following security technology is used to attract and trap people who attempt unauthorized or illicit utilization of the host system?

Correct Answer: C

QUESTION 14

Ray is a SOC analyst in a company named Queens Tech. One Day, Queens Tech is affected by a DoS/DDoS attack. For the containment of this incident, Ray and his team are trying to provide additional bandwidth to the network devices and increasing the capacity of the servers.
What is Ray and his team doing?

Correct Answer: D

QUESTION 15

Which of the following are the responsibilities of SIEM Agents?
* 1. Collecting data received from various devices sending data to SIEM before forwarding it to the central engine.
* 2. Normalizing data received from various devices sending data to SIEM before forwarding it to the central engine.
* 3. Co-relating data received from various devices sending data to SIEM before forwarding it to the central engine.
* 4. Visualizing data received from various devices sending data to SIEM before forwarding it to the central engine.

Correct Answer: C