option
Cuestiones
ayuda
daypo
buscar.php

ESOCA

COMENTARIOS ESTADÍSTICAS RÉCORDS
REALIZAR TEST
Título del Test:
ESOCA

Descripción:
las que no me se bien

Fecha de Creación: 2026/09/08

Categoría: Otros

Número Preguntas: 40

Valoración:(0)
COMPARTE EL TEST
Nuevo ComentarioNuevo Comentario
Comentarios
NO HAY REGISTROS
Temario:

Juliea a SOC analyst, while monitoring logs, noticed large TXT, NULL payloads. What does this indicate?. Concurrent VPN Connections Attempt. DNS Exfiltration Attempt. Covering Tracks Attempt. DHCP Starvation Attempt.

Which of the log storage method arranges event logs in the form of a circular buffer?. FIFO. LIFO. non-wrapping. wrapping.

Banter is a threat analyst in Christine Group of Industries. As a part of the job, he is currently formatting and structuring the raw data. He is at which stage of the threat intelligence life cycle?. Dissemination and Integration. Processing and Exploitation. Collection. Analysis and Production.

Which of the following Windows event is logged every time when a user tries to access the "Registry" key?. 4656. 4663. 4660. 4657.

What does Windows event ID 4740 indicate?. A user account was locked out. A user account was disabled. A user account was enabled. A user account was created.

Which of the following is a Threat Intelligence Platform?. SolarWinds MS. TC Complete. Keepnote. Apility.io.

A type of threat intelligent that find out the information about the attacker by misleading them is known as __________. Threat trending Intelligence. Detection Threat Intelligence. Operational Intelligence. Counter Intelligence.

Which of the following data source can be used to detect the traffic associated with Bad Bot User-Agents?. Windows Event Log. Web Server Logs. Router Logs. Switch Logs.

Jason, a SOC Analyst with Maximus Tech, was investigating Cisco ASA Firewall logs and came across the following log entry: May 06 2018 21:27:27 asa 1: %ASA -5 – 11008: User 'enable_15' executed the 'configure term' command What does the security level in the above log indicates?. Warning condition message. Critical condition message. Normal but significant message. Informational message.

Which of the following Windows Event Id will help you monitors file sharing across the network?. 7045. 4625. 5140. 4624.

The threat intelligence, which will help you, understand adversary intent and make informed decision to ensure appropriate security in alignment with risk. What kind of threat intelligence described above?. Tactical Threat Intelligence. Strategic Threat Intelligence. Functional Threat Intelligence. Operational Threat Intelligence.

Robin, a SOC engineer in a multinational company, is planning to implement a SIEM. He realized that his organization is capable of performing only Correlation, Analytics, Reporting, Retention, Alerting, and Visualization required for the SIEM implementation and has to take collection and aggregation services from a Managed Security Services Provider (MSSP). What kind of SIEM is Robin planning to implement?. Self-hosted, Self-Managed. Self-hosted, MSSP Managed. Hybrid Model, Jointly Managed. Cloud, Self-Managed.

John, a threat analyst at GreenTech Solutions, wants to gather information about specific threats against the organization. He started collecting information from various sources, such as humans, social media, chat room, and so on, and created a report that contains malicious activity. Which of the following types of threat intelligence did he use?. Strategic Threat Intelligence. Technical Threat Intelligence. Tactical Threat Intelligence. Operational Threat Intelligence.

John, SOC analyst wants to monitor the attempt of process creation activities from any of their Windows endpoints. Which of following Splunk query will help him to fetch related logs associated with process creation?. index=windows LogName=Security EventCode=4678 NOT (Account_Name=*$) .. .. ... .. index=windows LogName=Security EventCode=4688 NOT (Account_Name=*$) .. .. .. index=windows LogName=Security EventCode=3688 NOT (Account_Name=*$) .. .. .. index=windows LogName=Security EventCode=5688 NOT (Account_Name=*$) ... ... ...

Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket raised regarding a critical incident and Mike was assigned to handle the incident. During the process of incident handling, at one stage, he has performed incident analysis and validation to check whether the incident is a true incident or a false positive. Identify the stage in which he is currently in. Post-Incident Activities. Incident Recording and Assignment. Incident Triage. Incident Disclosure.

Which of the following stage executed after identifying the required event sources?. Identifying the monitoring Requirements. Defining Rule for the Use Case. Implementing and Testing the Use Case. Validating the event source against monitoring requirement.

Which of the following contains the performance measures, and proper project and time management details?. Incident Response Policy. Incident Response Tactics. Incident Response Process. Incident Response Procedures.

Which of the following threat intelligence helps cyber security professionals such as security operations managers, network operations center and incident responders to understand how the adversaries are expected to perform the attack on the organization, and the technical capabilities and goals of the attackers along with the attack vectors?. Analytical Threat Intelligence. Strategic Threat Intelligence. Operational Threat Intelligence. Tactical Threat Intelligence.

Which of the following service provides phishing protection and content filtering to manage the Internet experience on and off your network with the acceptable use or compliance policies?. Apility.io. Malstrom. OpenDNS. I-Blocklist.

Emmanuel is working as a SOC analyst in a company named Tobey Tech. The manager of Tobey Tech recently recruited an Incident Response Team (IRT) for his company. In the process of collaboration with the IRT, Emmanuel just escalated an incident to the IRT. What is the first step that the IRT will do to the incident escalated by Emmanuel?. Incident Analysis and Validation. Incident Recording. Incident Classification. Incident Prioritization.

A health corporation is implementing a SIEM solution to improve detection and response and comply with HIPAA requirements. They need the SIEM to efficiently collect, analyze, and correlate security events from network devices, servers, and security applications, and generate timely alerts for potential HIPAA violations. Which capability is needed to meet these needs?. Threat hunting and intelligence. Centralized SIEM implementation. Log management and security analytics. Log collection through agents.

Katie is a SOC analyst at an international financial corporation. Her team needs functionality so the system continuously scans logs for anomalies, identifies suspicious activities, notifies analysts when predefined security thresholds are reached, and generates incidents or tickets to ensure immediate response. It must provide details such as event type, duration, affected device, and OS version. Which function should she configure to achieve this?. Log collection. Alerting and reporting. Log normalization. Log parsing.

A SOC team notices malware-related incidents increased over the past Six months, primarily targeting endpoints through phishing campaigns. They need to present a report to security leadership to justify investing in advanced email filtering and end-user security training. Which SOC report best supports their case?. Monitoring summary report. Real-time monitoring report. Incident report. Trend analysis report.

A mid-sized hospital's SOC team has recently detected multiple malware incidents that disrupted access to patient records and caused operational inefficiencies. The SOC analysts have been tasked with eradicating current infections and preventing future attacks by addressing the underlying vulnerabilities that allowed the malware to breach defenses. As a SOC analyst, you need to recommend a step that directly targets weaknesses in the hospital's network infrastructure or system configurations exploited by the malware. Which eradication step would best address these root causes?. Fixing devices. Using antivirus tools for quarantine. Updating the malware database with vendor signatures. Implementing blacklist techniques for file execution.

A financial institution's SIEM is generating a high number of false positives, causing alert fatigue among SOC analysts. To reduce this burden and improve threat detection accuracy, the organization integrates Al capabilities into the SIEM. After implementation, the SOC team observes a significant decrease in redundant alerts, along with faster detection of genuine threats. Which Al capability contributed to this improvement?. Dynamic rule optimization. Rule validation and testing. Automated rule generation. Data integration enhancement.

You are working as a SOC analyst in a multinational company with multiple data centers and remote offices. Security logs are stored locally at each site, making it difficult to correlate incidents across different locations. Recently, an advanced persistent threat (APT) compromised multiple servers, but due to multiple sources of logs and inconsistent monitoring, the attack was detected only after significant data exfiltration. To improve visibility, streamline log analysis, and enable faster incident response, you need to implement a solution that aggregates logs from all sources into a unified system. Which solution Will you implement?. Centralized logging. Event tracing. Distributed logging. Local logging.

The SOC analyst at a national cybersecurity agency detected unusual system behavior on critical infrastructure servers. Initial scans flagged potential malware activity. Due to the sophisticated nature of the suspected attack, including registry modifications, process injection, and unauthorized tasks, the case was escalated to the forensic team. The forensic team suspects the malware is designed for stealthy data exfiltration. To assess the compromise, they captured system snapshots before and after suspected infection to identify unauthorized changes and anomalies. Which process are they following by capturing and comparing system snapshots to detect unauthorized changes?. Digital forensics. Signature-based detection. Threat intelligence gathering. Host integrity monitoring.

A security team is configuring a newly deployed SIEM system. With limited resources, they must prioritize monitoring scenarios that provide the greatest security benefit. The team understands an effective SIEM relies on well-defined use cases tailored to the organization's environment. Which factor should guide their selection of use cases?. Select use cases based on the availability and quality of data from existing data sources. Prioritize use cases that address zero-day attacks. Implement as many use cases as the SIEM supports to cover all threats. Focus on use cases required to meet industry compliance standards.

During a threat intelligence briefing, a SOC analyst comes across a classified report detailing a sophisticated cybercrime syndicate targeting executives of high-profile financial institutions. These adversaries rarely leave digital footprints and seem to anticipate security measures. Several breaches began with seemingly innocent conversations: a foreign journalist requesting an interview with a CEO and a "security consultant" offering free risk assessments. Further investigation reveals attackers socially engineered employees, manipulated trust, and extracted critical security details long before launching technical attacks. The analyst decides to focus on intelligence involving deception detection and psychological profiling to uncover true intent and methods. Which type of intelligence is the analyst leveraging?. Human Intelligence. Threat Intelligence Feeds. Open-Source Intelligence (OSINT). Technical Threat Intelligence.

A security analyst in a multinational corporation's Threat Intelligence team is tasked with enhancing detection of stealthy malware infections. During an investigation, the analyst observes an unusually high volume of DNS requests directed toward domains that follow patterns commonly associated with Domain Generation Algorithms (DGAs). Recognizing that these automated domain queries could indicate malware attempting to establish communication with command-and-control (C2) infrastructure, the analyst realizes existing detection may be insufficient. The security team needs to define intelligence requirements, including identifying critical data sources, refining detection criteria, and improving monitoring strategies. Which stage of the Cyber Threat Intelligence (CTI) process does this align with?. Automated tool. Requirement analysis. Filtering CTI. Intelligence buy-in.

A multinational cybersecurity firm wants to enhance its threat intelligence capabilities by integrating real-time threat feeds into Microsoft Sentinel. These feeds include malicious IPs, domains, file hashes, and attack patterns. The firm requires a standardized protocol that allows automated threat intelligence sharing so Sentinel continuously receives updated indicators from external sources in a structured format. Which Microsoft Sentinel data connector should be implemented to integrate threat intelligence feeds using an industry-standard protocol?. Threat Intelligence Platforms data connector. Syslog connector. TAXII data connector. Microsoft Defender for Cloud (Legacy) connector.

You are a Threat Hunter in an IT company's security team working to enhance threat hunting capabilities. You observed that relying solely on traditional security alerts often results in missed detections of sophisticated threats. To strengthen your approach, you decide to incorporate multiple data sources, including external threat intelligence feeds, internal security logs, network traffic data, and endpoint telemetry. To efficiently process this vast amount of data, you implement a new tool that can aggregate, normalize, and correlate threat intelligence with internal telemetry to gain a more holistic understanding of emerging threats and enhance detection accuracy. What key threat detection capability is being leveraged in this scenario?. Threat Reports. Intelligence Buy-In. Threat Trending. Data Integration.

You are working in a Cybersecurity Operations Center for PayOnline, which handles payment gateways for multiple applications. Your team monitors logs across firewalls, authentication servers, and endpoint detection tools. The team currently relies on manual log reviews, but the volume of raw, unstructured logs makes the process inefficient and error-prone. During a recent incident, the team struggled to extract relevant details from disorganized logs, delaying detection and response. The team decides to implement an automated log parsing solution that can transform unstructured logs into a structured format. Which log parsing technique should you implement to improve log data structuring and enable efficient querying and analysis?. Delimited parsing. Key-value extraction. Grok filters. Semantic parsing.

Which of the following stage executed after identifying the required event sources?. Identifying the monitoring Requirements. Defining Rule for the Use Case. Implementing and Testing the Use Case. Validating the event source against monitoring requirement.

A SOC analyst monitors network traffic to detect potential data exfiltration. The team uses a security solution that inspects data packets in real time as they traverse the network. During incident response, the solution struggles to analyze encrypted traffic, limiting effectiveness in identifying threats hidden within secure communications. Which security control, with this known limitation, is the SOC team relying on?. VPN. Packet filters. SSH. IPsec.

The Security Operations Center (SOC) team is investigating a suspected malware incident during the Analysis Phase of their incident response process. Their primary goal is to validate the initial detection, ensure the threat is real, and gather critical intelligence to understand the scope of the attack. Which action should the SOC team take to confirm initial findings and eliminate false alarms?. Verify generated logs. Verify false positives. Scan the enterprise environment and update the scope. Root-cause analysis.

A mid-sized financial institution's SOC is overwhelmed by thousands of daily alerts, many based on Indicators of Compromise (IoCs) such as suspicious IPs, hashes, and domains. These alerts lack context about whether they truly pose a threat. Analysts waste time on low-priority incidents while severe threats may be missed. The team lacks tools and intelligence to correlate IoCs with real-world threats, making prioritization difficult and causing alert fatigue. Which poses the greatest challenge in this environment?. Malware-centric and CTI are not equivalent. Information overload. Budget and enterprise skill. Distinguishing IoC from CTI.

ABC is a multinational company with multiple offices across the globe, and you are working as an L2 SOC analyst. You are implementing a centralized logging solution to enhance security monitoring. You must ensure that log messages from routers, firewalls, and servers across multiple remote offices are efficiently collected and forwarded to a central syslog server. To streamline this process, an intermediate component is deployed to receive log messages from different devices and forward them to the main syslog server. Which component in the syslog infrastructure performs this function?. Syslog Database. Syslog Collector. Syslog Listener. Syslog Relay.

David is a SOC analyst responsible for monitoring critical infrastructure. He detects unauthorized applications running on a high-privilege Windows server accessible only by a restricted set of users. The applications were not part of approved deployments, and installations occurred outside business hours. Logs indicate potential system configuration changes around the same timeframe. Which log should he examine to determine when and how these installations occurred?. Security event log. System event log. Setup event log. Application event log.

The SOC team at CyberSecure Corp is conducting a security review to identify anomalous log entries from firewall logs. The team needs to extract patterns such as email addresses, IP addresses, and URLs to detect unauthorized access attempts, phishing activities, and suspicious external communications. The SOC analyst applies various regular expressions (regex) patterns to filter and analyze logs efficiently. For example, they use \b\d{1,3}.\d{1,3}.\d{1,3}.\d{1,3}\b to match IPv4 addresses. Which regex pattern should the SOC analyst use to extract all hexadecimal color codes found in the logs?. (0[1-9]|1[0-2])/(0[1-9]|(1[0-2])/[0-9]|3[01])\d{4}. ([A-Fa-f0-9]{6}|[A-Fa-f0-9]{3}). [a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+.[a-zA-Z]{2,}. \b\d{1,3}.\d{1,3}.\d{1,3}.\d{1,3}\b.

Denunciar Test