最新(2023)EC-COUNCIL 312-39試験問題集 [Q43-Q64]

Share

最新(2023)EC-COUNCIL 312-39試験問題集

最適な練習法にはEC-COUNCIL 312-39試験の素晴らしい312-39試験問題PDF


EC-COUNCIL 312-39試験は、政府機関、金融機関、多国籍企業を含む世界中の多くの組織や企業に認められています。この認定は、候補者が組織の資産やデータをサイバー攻撃から保護するために必要なスキルと知識を持っていることを証明するため、雇用主にとって高く評価されています。また、この認定を取得することで、専門家は高い給与を得たり、サイバーセキュリティの分野でキャリアアップすることができます。

 

質問 # 43
Which of the following stage executed after identifying the required event sources?

  • A. Validating the event source against monitoring requirement
  • B. Identifying the monitoring Requirements
  • C. Defining Rule for the Use Case
  • D. Implementing and Testing the Use Case

正解:A


質問 # 44
Which of the following formula is used to calculate the EPS of the organization?

  • A. EPS = number of correlated events / time in seconds
  • B. EPS = average number of correlated events / time in seconds
  • C. EPS = number of security events / time in seconds
  • D. EPS = number of normalized events / time in seconds

正解:C

解説:


質問 # 45
An organization is implementing and deploying the SIEM with following capabilities.

What kind of SIEM deployment architecture the organization is planning to implement?

  • A. Self-hosted, Self-Managed
  • B. Self-hosted, MSSP Managed
  • C. Self-hosted, Jointly Managed
  • D. Cloud, MSSP Managed

正解:A

解説:


質問 # 46
If the SIEM generates the following four alerts at the same time:
I.Firewall blocking traffic from getting into the network alerts
II.SQL injection attempt alerts
III.Data deletion attempt alerts
IV.Brute-force attempt alerts
Which alert should be given least priority as per effective alert triaging?

  • A. I
  • B. III
  • C. II
  • D. IV

正解:A


質問 # 47
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.
Which of the following data source will he use to prepare the dashboard?

  • A. DNS/ Web Server logs with IP addresses.
  • B. DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.
  • C. Apache/ Web Server logs with IP addresses and Host Name.
  • D. IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.

正解:B

解説:


質問 # 48
An attacker exploits the logic validation mechanisms of an e-commerce website. He successfully purchases a product worth $100 for $10 by modifying the URL exchanged between the client and the server.
Original
URL: http://www.buyonline.com/product.aspx?profile=12
&debit=100
Modified URL: http://www.buyonline.com/product.aspx?profile=12
&debit=10
Identify the attack depicted in the above scenario.

  • A. Session Fixation Attack
  • B. SQL Injection Attack
  • C. Denial-of-Service Attack
  • D. Parameter Tampering Attack

正解:D

解説:


質問 # 49
Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket raised regarding a critical incident and Mike was assigned to handle the incident. During the process of incident handling, at one stage, he has performed incident analysis and validation to check whether the incident is a true incident or a false positive.
Identify the stage in which he is currently in.

  • A. Incident Triage
  • B. Incident Recording and Assignment
  • C. Post-Incident Activities
  • D. Incident Disclosure

正解:A

解説:


質問 # 50
David is a SOC analyst in Karen Tech. One day an attack is initiated by the intruders but David was not able to find any suspicious events.
This type of incident is categorized into?

  • A. True Negative Incidents
  • B. False positive Incidents
  • C. False Negative Incidents
  • D. True Positive Incidents

正解:A


質問 # 51
What does the Security Log Event ID 4624 of Windows 10 indicate?

  • A. Service added to the endpoint
  • B. An account was successfully logged on
  • C. New process executed
  • D. A share was assessed

正解:B


質問 # 52
Which of the following is a correct flow of the stages in an incident handling and response (IH&R) process?

  • A. Incident Recording -> Preparation -> Containment -> Incident Triage -> Recovery -> Eradication -> Post-Incident Activities
  • B. Containment -> Incident Recording -> Incident Triage -> Preparation -> Recovery -> Eradication -> Post-Incident Activities
  • C. Preparation -> Incident Recording -> Incident Triage -> Containment -> Eradication -> Recovery -> Post-Incident Activities
  • D. Incident Triage -> Eradication -> Containment -> Incident Recording -> Preparation -> Recovery -> Post-Incident Activities

正解:C


質問 # 53
Which of the following formula represents the risk levels?

  • A. Level of risk = Consequence * Likelihood
  • B. Level of risk = Consequence * Asset Value
  • C. Level of risk = Consequence * Severity
  • D. Level of risk = Consequence * Impact

正解:D


質問 # 54
An attacker, in an attempt to exploit the vulnerability in the dynamically generated welcome page, inserted code at the end of the company's URL as follows:
http://technosoft.com.com/<script>alert("WARNING: The application has encountered an error");</script>.
Identify the attack demonstrated in the above scenario.

  • A. SQL Injection Attack
  • B. Denial-of-Service Attack
  • C. Session Attack
  • D. Cross-site Scripting Attack

正解:D

解説:
Explanation


質問 # 55
Which of the following attack can be eradicated by disabling of "allow_url_fopen and allow_url_include" in the php.ini file?

  • A. Command Injection Attacks
  • B. URL Injection Attacks
  • C. LDAP Injection Attacks
  • D. File Injection Attacks

正解:B


質問 # 56
Charline is working as an L2 SOC Analyst. One day, an L1 SOC Analyst escalated an incident to her for further investigation and confirmation. Charline, after a thorough investigation, confirmed the incident and assigned it with an initial priority.
What would be her next action according to the SOC workflow?

  • A. She should communicate this incident to the media immediately
  • B. She should immediately contact the network administrator to solve the problem
  • C. She should formally raise a ticket and forward it to the IRT
  • D. She should immediately escalate this issue to the management

正解:C

解説:


質問 # 57
John, a SOC analyst, while monitoring and analyzing Apache web server logs, identified an event log matching Regex /(\.|(%|%25)2E)(\.|(%|%25)2E)(\/|(%|%25)2F|\\|(%|%25)5C)/i.
What does this event log indicate?

  • A. Parameter Tampering Attack
  • B. XSS Attack
  • C. Directory Traversal Attack
  • D. SQL injection Attack

正解:C

解説:


質問 # 58
Which of the following threat intelligence is used by a SIEM for supplying the analysts with context and
"situational awareness" by using threat actor TTPs, malware campaigns, tools used by threat actors.
1.Strategic threat intelligence
2.Tactical threat intelligence
3.Operational threat intelligence
4.Technical threat intelligence

  • A. 1 and 2
  • B. 3 and 4
  • C. 1 and 3
  • D. 2 and 3

正解:D


質問 # 59
Identify the attack, where an attacker tries to discover all the possible information about a target network before launching a further attack.

  • A. Ransomware Attack
  • B. Man-In-Middle Attack
  • C. Reconnaissance Attack
  • D. DoS Attack

正解:C


質問 # 60
Jony, a security analyst, while monitoring IIS logs, identified events shown in the figure below.

What does this event log indicate?

  • A. XSS Attack
  • B. SQL Injection Attack
  • C. Parameter Tampering Attack
  • D. Directory Traversal Attack

正解:C


質問 # 61
John as a SOC analyst is worried about the amount of Tor traffic hitting the network. He wants to prepare a dashboard in the SIEM to get a graph to identify the locations from where the TOR traffic is coming.
Which of the following data source will he use to prepare the dashboard?

  • A. DNS/ Web Server logs with IP addresses.
  • B. Apache/ Web Server logs with IP addresses and Host Name.
  • C. DHCP/Logs capable of maintaining IP addresses or hostnames with IPtoName resolution.
  • D. IIS/Web Server logs with IP addresses and user agent IPtouseragent resolution.

正解:B


質問 # 62
Identify the type of attack, an attacker is attempting on www.example.com website.

  • A. SQL Injection Attack
  • B. Denial-of-Service Attack
  • C. Session Attack
  • D. Cross-site Scripting Attack

正解:D


質問 # 63
Identify the event severity level in Windows logs for the events that are not necessarily significant, but may indicate a possible future problem.

  • A. Failure Audit
  • B. Information
  • C. Error
  • D. Warning

正解:D


質問 # 64
......

更新された検証済みの合格させる312-39リアル試験問題と解答:https://www.goshiken.com/EC-COUNCIL/312-39-mondaishu.html

問題集返金保証付きの312-39問題集公式問題集:https://drive.google.com/open?id=1YvOump_INMAMZz7qmoSDwfDhbo8Rkpwq