Skip to content

312-39 Practice Questions

Prepare for 312-39 with more than an answer.

218 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$450 USD
Level
Associate
Valid for
3 years
Domains covered on the exam 6
  1. Security Operations and Management20%
  2. Understanding Cyber Threats, IoCs, and Attack Methodology15%
  3. Incidents, Events, and Logging18%
  4. Incident Detection with Security Information and Event Management (SIEM)25%
  5. Enhanced Incident Detection with Threat Intelligence12%
  6. Incident Response10%
  1. 1

    A manufacturing company is setting up its first internal SOC. The CISO is deciding between a dedicated, in-house SOC and a co-managed model with a Managed Security Service Provider (MSSP). The company has a small, but skilled, IT security team and operates 24/7 production lines that cannot tolerate downtime. What is the strongest justification for choosing the co-managed model in this scenario?

    Show answer details

    Correct answer: C

    The co-managed model offers the best of both worlds for this scenario. The MSSP can provide the expensive and difficult-to-staff 24/7 monitoring, handling initial alert triage. The skilled in-house team can then focus on higher-level tasks, such as threat hunting and incident response, bringing their deep contextual understanding of the company's critical manufacturing and Operational Technology (OT) systems. This synergy is crucial for protecting an environment where downtime is unacceptable. The in-house team understands what is normal for their unique environment, which an MSSP alone would lack.

  2. 2

    A SOC analyst is reviewing firewall logs and sees a large number of denied connections from a single external IP address to a wide range of ports on a web server. The ports being scanned are not in sequential order. What is this activity called?

    Show answer details

    Correct answer: C

    This activity is a port scan, a common reconnaissance technique used by attackers to discover open and listening services on a target system. The fact that many ports are being probed from a single source is the key indicator. The non-sequential nature of the scan is a common tactic used by tools like Nmap to evade simple, pattern-based detection.

  3. 3

    A SOC is implementing a new SOAR (Security Orchestration, Automation, and Response) platform. Which of the following use cases is the BEST initial candidate for automation to provide the most immediate value in reducing analyst workload?

    Show answer details

    Correct answer: B

    Phishing email analysis is an ideal initial use case for SOAR. It is a high-volume, repetitive task with a well-defined process. A SOAR playbook can automatically: 1) extract observables (URLs, hashes, IPs) from the email, 2) query threat intelligence platforms for reputation, 3) detonate attachments in a sandbox, and 4) present the enriched data to an analyst for a final decision or even take automated actions like deleting similar emails. This provides immediate, significant time savings. Automating complex APT investigations is an advanced goal that requires a very mature SOAR implementation.

  4. 4

    A new threat actor group is known to use a specific Domain Generation Algorithm (DGA) for its C2 communications. What are the TWO most effective ways a SOC can detect this activity? (Select TWO)

    Show answer details

    Correct answer: B, C

  5. 5

    A SOC analyst is reviewing the following simplified incident response workflow diagram. At which stage should the analyst first create a ticket in the organization's incident tracking system?

    flowchart TD A[Monitoring Systems Generate Alert] --> B{Initial Triage}; B -->|False Positive| C[Close & Document]; B -->|Potential Incident| D{Analysis & Scoping}; D --> E[Containment Actions]; E --> F[Eradication & Recovery]; F --> G[Post-Incident Review];

    Show answer details

    Correct answer: B

    The best practice is to create an official incident ticket after the initial triage (Stage B) confirms that an alert is a potential incident and not an obvious false positive. Creating a ticket for every single raw alert (Stage A) would flood the system with noise. Once an alert is validated and requires further investigation (moving to Stage D), it should be formally tracked. This ensures that all legitimate investigations are documented, assigned, and managed through their lifecycle.

  6. 6

    A SOC analyst at a pharmaceutical company is investigating a high-severity alert from their SIEM. The alert triggered on a correlation rule that detects a successful VPN login from an un-recognized IP address followed within two minutes by the execution of powershell.exe -e JABj.... The Base64 encoded string is too long to be fully displayed in the alert summary. What is the analyst's most critical immediate next step to determine the nature of the potential incident?

    Show answer details

    Correct answer: C

    The most critical immediate step is to understand what the PowerShell command is attempting to do. Blocking the IP or isolating the host are containment actions that should be taken, but not before gaining context. Without understanding the payload, the analyst cannot determine the scope or severity of the incident. Decoding the Base64 string from the full log entry will reveal the actual commands being executed, providing the necessary intelligence to guide subsequent containment and eradication steps.

  7. 7

    A junior SOC analyst is tasked with creating a new SIEM correlation rule to detect potential SQL injection attacks. The analyst proposes the following logic: "Alert if a web server log from the external DMZ contains the string 'UNION SELECT' OR '1=1'." Why is this rule likely to be ineffective in a modern SOC?

    Show answer details

    Correct answer: B

    Modern attackers rarely use plain-text SQL injection strings. They employ various encoding techniques (URL encoding, Base64, etc.) and obfuscation methods to bypass simple string-matching rules. A rule that only looks for literal strings like 'UNION SELECT' is trivial to evade and will result in a high number of false negatives (missed attacks). A more effective rule would need to look for patterns, special characters, or use more advanced analytics that can decode and normalize log data before inspection.

  8. 8

    A SOC team for a global logistics company has integrated several new threat intelligence feeds into their TIP. An analyst observes a sudden, massive spike in alerts related to malicious IP addresses, overwhelming the Tier 1 team. Upon investigation, many of these IPs belong to a major Content Delivery Network (CDN). Which TWO of the following actions should the analyst prioritize to mitigate this issue while maintaining security posture? (Select TWO)

    Show answer details

    Correct answer: B, C

  9. 9

    During a threat hunting exercise, a SOC analyst is proactively searching for signs of lateral movement. The analyst formulates a hypothesis that an attacker is using PsExec for remote command execution. Which data source would be MOST valuable for validating this hypothesis?

    Show answer details

    Correct answer: C

    PsExec works by installing a temporary service (PSEXESVC) on the remote machine to execute commands. This action generates a 'A service was installed in the system' event with Event ID 4697 in the Windows Security Log on the target host. Searching for this specific event across multiple workstations is a high-fidelity method for detecting PsExec usage. While firewall logs show the necessary SMB traffic, they don't confirm what the traffic is for. DNS logs are too generic. Process creation logs on the source machine would show psexec.exe running, but logs on the target machine provide definitive proof of the lateral movement.

  10. 10

    A SOC Manager is reviewing the monthly metrics and notices that the Mean Time to Detect (MTTD) has increased significantly, while the Mean Time to Respond (MTTR) has remained stable. What is the MOST likely cause for this trend?

    Show answer details

    Correct answer: B

    MTTD measures the time from when an attack occurs until it is detected. A rising MTTD indicates a problem with the detection capabilities. This is often caused by poorly tuned SIEM rules, outdated threat intelligence, or gaps in log source coverage, leading to alerts being missed or delayed. Since MTTR (the time from detection to resolution) is stable, it means the response team is performing their job effectively once an incident is identified. Therefore, the problem lies in the detection phase, not the response phase.

Create an account to continue.