Free 312-39V2 Eccouncil 312-39V2 Practice Test Question

Loading demo links...

Showing 1–2 of 2 questions

Question 1 (Topic 1)

The Security Operations Center (SOC) team is investigating a suspected malware incident during the Analysis Phase of their incident response process. Their primary goal is to validate the initial detection, ensure the threat is real, and gather critical intelligence to understand the scope of the attack. Which of the following actions should the SOC team take to confirm their initial findings and eliminate false alarms?

Select an option, then click Submit answer.

  • Verify generated logs
  • Scan the enterprise environment and update the scope
  • Root-cause analysis
  • Verify false positives
Question 2 (Topic 1)

A threat hunter analyzing an infected endpoint finds that malicious processes keep reappearing even after termination, making traditional remediation ineffective. The user of the endpoint reports occasional system slowdowns, abnormal pop-ups, and unauthorized application launches. Upon deeper inspection, the threat hunter discovers that the system has multiple scheduled tasks executing unknown scripts at specific intervals, along with suspicious registry modifications that enable automatic script execution upon startup. Further investigation reveals that the endpoint has made occasional outbound connections to an unclassified external server, though the traffic is encrypted and intermittent. Additionally, the organization recently experienced multiple failed login attempts on privileged accounts originating from the same subnet, raising concerns about potential credential theft or lateral movement. With the possibility of persistence mechanisms, lateral movement, or external C2 activity, which signs should the threat hunter look out for to confirm and mitigate the threat?

Select an option, then click Submit answer.

  • Network-Based Artifacts
  • Threat Intelligence & Adversary
  • Indicators of Attack (IoAs)
  • Host-Based Artifacts