[2022年最新] 高合格率な312-39テストアンサーかつEC-COUNCIL 312-39テストPDF [Q20-Q38]

Share

[2022年最新] 高合格率な312-39テストアンサーかつEC-COUNCIL 312-39テストPDF

完璧312-39問題集試験問題と解答でパス保証されます

質問 20
Which of the following threat intelligence helps cyber security professionals such as security operations managers, network operations center and incident responders to understand how the adversaries are expected to perform the attack on the organization, and the technical capabilities and goals of the attackers along with the attack vectors?

  • A. Strategic Threat Intelligence
  • B. Tactical Threat Intelligence
  • C. Operational Threat Intelligence
  • D. Analytical Threat Intelligence

正解: B

 

質問 21
Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket raised regarding a critical incident and Mike was assigned to handle the incident. During the process of incident handling, at one stage, he has performed incident analysis and validation to check whether the incident is a true incident or a false positive.
Identify the stage in which he is currently in.

  • A. Incident Recording and Assignment
  • B. Post-Incident Activities
  • C. Incident Triage
  • D. Incident Disclosure

正解: A

 

質問 22
Which of the following contains the performance measures, and proper project and time management details?

  • A. Incident Response Policy
  • B. Incident Response Tactics
  • C. Incident Response Procedures
  • D. Incident Response Process

正解: C

 

質問 23
What does Windows event ID 4740 indicate?

  • A. A user account was locked out.
  • B. A user account was created.
  • C. A user account was disabled.
  • D. A user account was enabled.

正解: A

 

質問 24
Which of the following Windows event is logged every time when a user tries to access the "Registry" key?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

正解: A

 

質問 25
Identify the HTTP status codes that represents the server error.

  • A. 2XX
  • B. 1XX
  • C. 4XX
  • D. 5XX

正解: D

 

質問 26
What does the HTTP status codes 1XX represents?

  • A. Redirection
  • B. Client error
  • C. Informational message
  • D. Success

正解: C

 

質問 27
Banter is a threat analyst in Christine Group of Industries. As a part of the job, he is currently formatting and structuring the raw data.
He is at which stage of the threat intelligence life cycle?

  • A. Analysis and Production
  • B. Processing and Exploitation
  • C. Dissemination and Integration
  • D. Collection

正解: B

 

質問 28
According to the Risk Matrix table, what will be the risk level when the probability of an attack is very low and the impact of that attack is major?

  • A. Extreme
  • B. Medium
  • C. High
  • D. Low

正解: D

 

質問 29
Chloe, a SOC analyst with Jake Tech, is checking Linux systems logs. She is investigating files at /var/log/ wtmp.
What Chloe is looking at?

  • A. Login records
  • B. Error log
  • C. General message and system-related stuff
  • D. System boot log

正解: A

 

質問 30
What does [-n] in the following checkpoint firewall log syntax represents?
fw log [-f [-t]] [-n] [-l] [-o] [-c action] [-h host] [-s starttime] [-e endtime] [-b starttime endtime] [-u unification_scheme_file] [-m unification_mode(initial|semi|raw)] [-a] [-k (alert name|all)] [-g] [logfile]

  • A. Display detailed log chains (all the log segments a log record consists of)
  • B. Display account log records only
  • C. Display both the date and the time for each log record
  • D. Speed up the process by not performing IP addresses DNS resolution in the Log files

正解: D

 

質問 31
Jane, a security analyst, while analyzing IDS logs, detected an event matching Regex
/((\%3C)|<)((\%69)|i|(\% 49))((\%6D)|m|(\%4D))((\%67)|g|(\%47))[^\n]+((\%3E)|>)/|.
What does this event log indicate?

  • A. SQL Injection Attack
  • B. XSS Attack
  • C. Directory Traversal Attack
  • D. Parameter Tampering Attack

正解: B

 

質問 32
Which of the following service provides phishing protection and content filtering to manage the Internet experience on and off your network with the acceptable use or compliance policies?

  • A. I-Blocklist
  • B. OpenDNS
  • C. Apility.io
  • D. Malstrom

正解: B

 

質問 33
Identify the type of attack, an attacker is attempting on www.example.com website.

  • A. SQL Injection Attack
  • B. Session Attack
  • C. Denial-of-Service Attack
  • D. Cross-site Scripting Attack

正解: D

 

質問 34
Which of the following technique involves scanning the headers of IP packets leaving a network to make sure that the unauthorized or malicious traffic never leaves the internal network?

  • A. Throttling
  • B. Ingress Filtering
  • C. Rate Limiting
  • D. Egress Filtering

正解: D

 

質問 35
Which of the following attack can be eradicated by converting all non-alphanumeric characters to HTML character entities before displaying the user input in search engines and forums?

  • A. Broken Access Control Attacks
  • B. XSS Attacks
  • C. Session Management Attacks
  • D. Web Services Attacks

正解: B

 

質問 36
Identify the attack in which the attacker exploits a target system through publicly known but still unpatched vulnerabilities.

  • A. Zero-Day Attack
  • B. DNS Poisoning Attack
  • C. DHCP Starvation
  • D. Slow DoS Attack

正解: A

 

質問 37
Which one of the following is the correct flow for Setting Up a Computer Forensics Lab?

  • A. Planning and budgeting -> Physical location and structural design considerations -> Forensics lab licensing ->Work area considerations -> Human resource considerations -> Physical security recommendations
  • B. Planning and budgeting -> Physical location and structural design considerations -> Work area considerations -> Human resource considerations -> Physical security recommendations -> Forensics lab licensing
  • C. Planning and budgeting -> Physical location and structural design considerations-> Forensics lab licensing -> Human resource considerations -> Work area considerations -> Physical security recommendations
  • D. Planning and budgeting -> Forensics lab licensing -> Physical location and structural design considerations -> Work area considerations -> Physical security recommendations -> Human resource considerations

正解: B

 

質問 38
......


EC-COUNCIL 312-39 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • SIEMユースケース開発プロセスの実践的な経験を積む
  • 企業における脅威の監視と分析を計画、整理、実行する
トピック 2
  • 追加の支援のためにインシデントを適切なチームにエスカレーションできる
  • 多様で、異種の、絶えず変化する脅威情報を利用できる
トピック 3
  • セキュリティ情報とイベント管理の経験と幅広い知識を得る
  • 新たな脅威パターンを監視し、セキュリティ脅威分析を実行できる
トピック 4
  • SIEMソリューションのアーキテクチャ、実装、および微調整を理解する
  • SOCプロセス、手順、テクノロジー、およびワークフローに関する知識を習得する
トピック 5
  • 脅威のケース(相関ルール)を作成し、レポートを作成する
  • セキュリティの脅威、攻撃、脆弱性に関する基本的な理解と深い知識を得ることができる
トピック 6
  • 脅威インテリジェンスをSIEMに統合する知識を習得する
  • 攻撃者のツール、戦術、および手順を認識できる
トピック 7
  • アラートトリアージプロセスの実践的な経験を積む
  • 分析方法と結果のブリーフィングとレポートを作成できる
トピック 8
  • SIEM展開全体で広く使用されているユースケースを学ぶ
  • インシデント対応プロセスの知識を得る
トピック 9
  • セキュリティイベントとログの収集、監視、分析を実行できる
  • SIEMソリューションの管理に関する知識を得る

 

312-39試験問題高合格率な312-39問題集PDF:https://jp.fast2test.com/312-39-premium-file.html

312-39のPDF問題集最近更新された問題:https://drive.google.com/open?id=1wEcx3MNdxfIzAjUW0uetusMkj1KtPth-


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어