
Sep 08, 2021 Step by Step Guide to Prepare for 312-39 Exam BrainDumps
EC-COUNCIL CSA 312-39 Real Exam Questions and Answers FREE Updated on 2021
NEW QUESTION 22
Which of the following attack can be eradicated by using a safe API to avoid the use of the interpreter entirely?
- A. LDAP Injection Attacks
- B. SQL Injection Attacks
- C. Command Injection Attacks
- D. File Injection Attacks
Answer: B
NEW QUESTION 23
Which of the following attack can be eradicated by disabling of "allow_url_fopen and allow_url_include" in the php.ini file?
- A. URL Injection Attacks
- B. LDAP Injection Attacks
- C. Command Injection Attacks
- D. File Injection Attacks
Answer: A
NEW QUESTION 24
Which of the following security technology is used to attract and trap people who attempt unauthorized or illicit utilization of the host system?
- A. Honeypot
- B. Firewall
- C. De-Militarized Zone (DMZ)
- D. Intrusion Detection System
Answer: A
NEW QUESTION 25
Which of the following event detection techniques uses User and Entity Behavior Analytics (UEBA)?
- A. Signature-based detection
- B. Anomaly-based detection
- C. Rule-based detection
- D. Heuristic-based detection
Answer: B
NEW QUESTION 26
Which attack works like a dictionary attack, but adds some numbers and symbols to the words from the dictionary and tries to crack the password?
- A. Bruteforce Attack
- B. Hybrid Attack
- C. Birthday Attack
- D. Rainbow Table Attack
Answer: A
NEW QUESTION 27
David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not able to find any suspicious events.
This type of incident is categorized into?
- A. False Negative Incidents
- B. True Positive Incidents
- C. False positive Incidents
- D. True Negative Incidents
Answer: D
NEW QUESTION 28
Which of the following command is used to enable logging in iptables?
- A. $ iptables -B INPUT -j LOG
- B. $ iptables -A INPUT -j LOG
- C. $ iptables -B OUTPUT -j LOG
- D. $ iptables -A OUTPUT -j LOG
Answer: D
NEW QUESTION 29
Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket raised regarding a critical incident and Mike was assigned to handle the incident. During the process of incident handling, at one stage, he has performed incident analysis and validation to check whether the incident is a true incident or a false positive.
Identify the stage in which he is currently in.
- A. Incident Recording and Assignment
- B. Incident Disclosure
- C. Incident Triage
- D. Post-Incident Activities
Answer: A
NEW QUESTION 30
Which of the following service provides phishing protection and content filtering to manage the Internet experience on and off your network with the acceptable use or compliance policies?
- A. I-Blocklist
- B. Apility.io
- C. OpenDNS
- D. Malstrom
Answer: C
NEW QUESTION 31
Which one of the following is the correct flow for Setting Up a Computer Forensics Lab?
- A. Planning and budgeting -> Physical location and structural design considerations -> Forensics lab licensing ->Work area considerations -> Human resource considerations -> Physical security recommendations
- B. Planning and budgeting -> Physical location and structural design considerations-> Forensics lab licensing -> Human resource considerations -> Work area considerations -> Physical security recommendations
- C. Planning and budgeting -> Physical location and structural design considerations -> Work area considerations -> Human resource considerations -> Physical security recommendations -> Forensics lab licensing
- D. Planning and budgeting -> Forensics lab licensing -> Physical location and structural design considerations -> Work area considerations -> Physical security recommendations -> Human resource considerations
Answer: C
NEW QUESTION 32
Identify the password cracking attempt involving a precomputed dictionary of plaintext passwords and their corresponding hash values to crack the password.
- A. Syllable Attack
- B. Dictionary Attack
- C. Rainbow Table Attack
- D. Bruteforce Attack
Answer: B
NEW QUESTION 33
Which of the following factors determine the choice of SIEM architecture?
- A. DNS Configuration
- B. SMTP Configuration
- C. DHCP Configuration
- D. Network Topology
Answer: A
NEW QUESTION 34
Which of the following Windows features is used to enable Security Auditing in Windows?
- A. Windows Defender
- B. Windows Firewall
- C. Local Group Policy Editor
- D. Bitlocker
Answer: C
NEW QUESTION 35
In which log collection mechanism, the system or application sends log records either on the local disk or over the network.
- A. push-based
- B. rule-based
- C. signature-based
- D. pull-based
Answer: B
NEW QUESTION 36
Which of the following formula represents the risk levels?
- A. Level of risk = Consequence * Likelihood
- B. Level of risk = Consequence * Asset Value
- C. Level of risk = Consequence * Severity
- D. Level of risk = Consequence * Impact
Answer: D
NEW QUESTION 37
In which of the following incident handling and response stages, the root cause of the incident must be found from the forensic results?
- A. Evidence Gathering
- B. Eradication
- C. Systems Recovery
- D. Evidence Handling
Answer: A
NEW QUESTION 38
What does Windows event ID 4740 indicate?
- A. A user account was enabled.
- B. A user account was locked out.
- C. A user account was created.
- D. A user account was disabled.
Answer: B
NEW QUESTION 39
John, a SOC analyst, while monitoring and analyzing Apache web server logs, identified an event log matching Regex /(\.|(%|%25)2E)(\.|(%|%25)2E)(\/|(%|%25)2F|\\|(%|%25)5C)/i.
What does this event log indicate?
- A. XSS Attack
- B. SQL injection Attack
- C. Parameter Tampering Attack
- D. Directory Traversal Attack
Answer: A
NEW QUESTION 40
John, a threat analyst at GreenTech Solutions, wants to gather information about specific threats against the organization. He started collecting information from various sources, such as humans, social media, chat room, and so on, and created a report that contains malicious activity.
Which of the following types of threat intelligence did he use?
- A. Strategic Threat Intelligence
- B. Technical Threat Intelligence
- C. Tactical Threat Intelligence
- D. Operational Threat Intelligence
Answer: D
NEW QUESTION 41
Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry:
May 06 2018 21:27:27 asa 1: %ASA -5 - 11008: User 'enable_15' executed the 'configure term' command What does the security level in the above log indicates?
- A. Critical condition message
- B. Normal but significant message
- C. Warning condition message
- D. Informational message
Answer: C
NEW QUESTION 42
According to the forensics investigation process, what is the next step carried out right after collecting the evidence?
- A. Call Organizational Disciplinary Team
- B. Send it to the nearby police station
- C. Set a Forensic lab
- D. Create a Chain of Custody Document
Answer: D
NEW QUESTION 43
Which of the following steps of incident handling and response process focus on limiting the scope and extent of an incident?
- A. Containment
- B. Eradication
- C. Identification
- D. Data Collection
Answer: A
NEW QUESTION 44
Which of the following tool can be used to filter web requests associated with the SQL Injection attack?
- A. UrlScan
- B. Nmap
- C. ZAP proxy
- D. Hydra
Answer: A
NEW QUESTION 45
The threat intelligence, which will help you, understand adversary intent and make informed decision to ensure appropriate security in alignment with risk.
What kind of threat intelligence described above?
- A. Functional Threat Intelligence
- B. Strategic Threat Intelligence
- C. Tactical Threat Intelligence
- D. Operational Threat Intelligence
Answer: B
NEW QUESTION 46
Which of the following attack can be eradicated by filtering improper XML syntax?
- A. CAPTCHA Attacks
- B. Web Services Attacks
- C. Insufficient Logging and Monitoring Attacks
- D. SQL Injection Attacks
Answer: D
NEW QUESTION 47
......
Ultimate Guide to Prepare 312-39 Certification Exam for EC-COUNCIL CSA: https://www.actual4labs.com/EC-COUNCIL/312-39-actual-exam-dumps.html
312-39 Ultimate Study Guide: https://drive.google.com/open?id=1x7NRIkS_Jcdnxr9n14wB0Na4u1RvbNB1