Certified SOC Analyst Free Sample Questions

20 free sample questions218 in the full practice test

Try simulator

312-39 Sample Questions

  1. Question 1

    A SOC analyst at a pharmaceutical company is investigating a high-severity alert from their SIEM. The alert triggered on a correlation rule that detects a successful VPN login from an un-recognized IP address followed within two minutes by the execution of powershell.exe -e JABj.... The Base64 encoded string is too long to be fully displayed in the alert summary. What is the analyst's most critical immediate next step to determine the nature of the potential incident?

    Answer and explanation

    Correct answer: C

    The most critical immediate step is to understand what the PowerShell command is attempting to do. Blocking the IP or isolating the host are containment actions that should be taken, but not before gaining context. Without understanding the payload, the analyst cannot determine the scope or severity of the incident. Decoding the Base64 string from the full log entry will reveal the actual commands being executed, providing the necessary intelligence to guide subsequent containment and eradication steps.

  2. Question 2

    A junior SOC analyst is tasked with creating a new SIEM correlation rule to detect potential SQL injection attacks. The analyst proposes the following logic: "Alert if a web server log from the external DMZ contains the string 'UNION SELECT' OR '1=1'." Why is this rule likely to be ineffective in a modern SOC?

    Answer and explanation

    Correct answer: B

    Modern attackers rarely use plain-text SQL injection strings. They employ various encoding techniques (URL encoding, Base64, etc.) and obfuscation methods to bypass simple string-matching rules. A rule that only looks for literal strings like 'UNION SELECT' is trivial to evade and will result in a high number of false negatives (missed attacks). A more effective rule would need to look for patterns, special characters, or use more advanced analytics that can decode and normalize log data before inspection.

  3. Question 3

    Multiple answers

    A SOC team for a global logistics company has integrated several new threat intelligence feeds into their TIP. An analyst observes a sudden, massive spike in alerts related to malicious IP addresses, overwhelming the Tier 1 team. Upon investigation, many of these IPs belong to a major Content Delivery Network (CDN). Which TWO of the following actions should the analyst prioritize to mitigate this issue while maintaining security posture? (Select TWO)

    Answer and explanation

    Correct answers: B, C

  4. Question 4

    During a threat hunting exercise, a SOC analyst is proactively searching for signs of lateral movement. The analyst formulates a hypothesis that an attacker is using PsExec for remote command execution. Which data source would be MOST valuable for validating this hypothesis?

    Answer and explanation

    Correct answer: C

    PsExec works by installing a temporary service (PSEXESVC) on the remote machine to execute commands. This action generates a 'A service was installed in the system' event with Event ID 4697 in the Windows Security Log on the target host. Searching for this specific event across multiple workstations is a high-fidelity method for detecting PsExec usage. While firewall logs show the necessary SMB traffic, they don't confirm what the traffic is for. DNS logs are too generic. Process creation logs on the source machine would show psexec.exe running, but logs on the target machine provide definitive proof of the lateral movement.

  5. Question 5

    A SOC Manager is reviewing the monthly metrics and notices that the Mean Time to Detect (MTTD) has increased significantly, while the Mean Time to Respond (MTTR) has remained stable. What is the MOST likely cause for this trend?

    Answer and explanation

    Correct answer: B

    MTTD measures the time from when an attack occurs until it is detected. A rising MTTD indicates a problem with the detection capabilities. This is often caused by poorly tuned SIEM rules, outdated threat intelligence, or gaps in log source coverage, leading to alerts being missed or delayed. Since MTTR (the time from detection to resolution) is stable, it means the response team is performing their job effectively once an incident is identified. Therefore, the problem lies in the detection phase, not the response phase.

  6. Question 6

    True or False: In the Cyber Kill Chain model, the 'Installation' phase always occurs before the 'Command and Control' phase.

    Answer and explanation

    Correct answer: A

    True. According to the Lockheed Martin Cyber Kill Chain model, the 'Installation' phase, where malware establishes persistence on the victim's system, precedes the 'Command and Control' (C2) phase. During the C2 phase, the installed malware 'calls home' to the attacker's infrastructure to receive instructions. Persistence must be established first to ensure the C2 channel can be maintained.

  7. Question 7

    An organization's incident response policy mandates that after containing a malware outbreak on several workstations, the next step is 'Eradication'. Which of the following activities is a core part of the Eradication phase?

    Answer and explanation

    Correct answer: D

    The Eradication phase of the incident response lifecycle focuses on completely removing the threat from the environment. This includes deleting the malware, removing persistence mechanisms (like registry keys or scheduled tasks), and eliminating any other tools or backdoors left by the attacker. Isolation is part of Containment, restoring data is part of Recovery, and lessons learned is the final post-incident phase.

  8. Question 8

    A SOC analyst needs to write a query in a Splunk-based SIEM to find all successful RDP login events (EventCode=4624) from IP addresses outside of the company's designated country code (US). Which of the following Splunk queries is the best approach to accomplish this?

    Answer and explanation

    Correct answer: B

    This query correctly filters for the specific Windows event for a successful logon (EventCode=4624), then uses the iplocation command to enrich the events with geographic data based on the source IP address (src_ip). Finally, it uses a search command to filter those enriched events to show only those where the Country field is not equal to 'US'. The other options are incorrect or less efficient.

  9. Question 9

    A financial services firm is required to comply with a regulation that mandates a log retention period of seven years for all authentication and transaction logs. The firm's current SIEM solution stores all data in 'hot' storage for fast querying, which is becoming prohibitively expensive for long-term retention. What is the most appropriate architectural solution for the SOC to propose?

    Answer and explanation

    Correct answer: B

    A data tiering strategy is the industry-standard solution for balancing performance and cost in long-term log retention. Logs are kept in expensive, high-performance 'hot' storage for a short period (e.g., 30-90 days) for immediate analysis. After that, they are moved to cheaper, slower 'warm' or 'cold' storage (like AWS S3 Glacier or an on-premise NAS). This meets the compliance requirement for retention without the exorbitant cost of keeping all data in hot storage. Data can still be re-ingested or queried from cold storage if needed for a forensic investigation, albeit more slowly.

  10. Question 10

    A SOC analyst is investigating an alert indicating that a sensitive file was accessed on a file server from a user account that has been dormant for over a year. Which attack methodology concept does this activity MOST closely align with?

    Answer and explanation

    Correct answer: D

    This scenario describes a specific Tactic, Technique, and Procedure (TTP). The tactic is 'Persistence' or 'Defense Evasion', the technique is 'Valid Accounts', and the specific procedure is the use of a dormant account to access resources. An IoC is the evidence itself (e.g., the log entry), not the methodology. Zero-day and DoS are types of attacks, but the concept of using a dormant account is a classic TTP employed by attackers to blend in and avoid detection.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 218 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon