Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Newly Released ECCouncil 312-39 Exam PDF

Page: 10 / 15
Total 200 questions

Certified SOC Analyst (CSA v2) Questions and Answers

Question 37

At 10:30 AM, during routine monitoring, Tier 1 SOC analyst Jennifer detects unusual network traffic and confirms an active LockBit ransomware infection targeting systems in the finance department. She escalates to the SOC lead, Sarah, who activates the Incident Response Team (IRT) and instructs the network team to isolate the finance department’s VLAN to prevent further spread across the network. Which phase of the Incident Response process is currently being implemented?

Options:

A.

Evidence gathering and forensic analysis

B.

Eradication

C.

Notification

D.

Containment

Question 38

A SIEM alert is triggered due to unusual network traffic involving NetBIOS. The system log shows: “The TCP/IP NetBIOS Helper service entered the running state.” Concurrently, Windows Security Event ID 4624 (“An account was successfully logged on”) appears for multiple machines within a short time frame. The logon type is 3 (Network logon). Which of the following security incidents is the SIEM detecting?

Options:

A.

An attacker performing lateral movement within the network

B.

A user connecting to shared files from multiple workstations

C.

A network administrator conducting routine maintenance

D.

A malware infection spreading via SMB protocol

Question 39

At GlobalTech, the SOC team detects a suspicious ransomware outbreak affecting multiple endpoints. After successfully isolating the infected systems from the network, the Digital Forensics team begins their investigation. They deploy a forensics workstation to acquire RAM dumps, extract Windows Event Logs, and collect network PCAP files from the compromised hosts. Which phase of the Incident Response lifecycle is currently underway?

Options:

A.

Recovery

B.

Evidence gathering and forensic analysis

C.

Containment

D.

Eradication

Question 40

The SOC team at GlobalTech has finished patching a critical vulnerability exploited during a ransomware attack. The team is now restoring 2.3 TB of encrypted data from their Veeam backup system, rebuilding 23 compromised workstations identified through SIEM logs, and re-enabling network access for the finance department after validating systems are clean. Which Incident Response phase is this?

Options:

A.

Post-incident activities

B.

Containment

C.

Eradication

D.

Recovery

Page: 10 / 15
Total 200 questions