Official Bank 0/99

Certified SOC Analyst (CSA) (312-39) - EC Council Actual Exam Questions

Last updated on May 13, 2026

97% Exam Compliance
99 Total Questions
1
Question

Chloe, a SOC analyst with Jake Tech, is checking Linux systems logs. She is investigating files at /var/log/ wtmp. What Chloe is looking at?

Options
A

Error log

B

System boot log

C

General message and system-related stuff

D

Login records

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

According to the Risk Matrix table, what will be the risk level when the probability of an attack is very low and the impact of that attack is major?

Options
A

High

B

Extreme

C

Low

D

Medium

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

Mike is an incident handler for PNP Infosystems Inc. One day, there was a ticket raised regarding a critical incident and Mike was assigned to handle the incident. During the process of incident handling, at one stage, he has performed incident analysis and validation to check whether the incident is a true incident or a false positive. Identify the stage in which he is currently in.

Options
A

Post-Incident Activities

B

Incident Recording and Assignment

C

Incident Triage

D

Incident Disclosure

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

Which of the following command is used to enable logging in iptables?

Options
A

$ iptables -B INPUT -j LOG

B

$ iptables -A OUTPUT -j LOG

C

$ iptables -A INPUT -j LOG

D

$ iptables -B OUTPUT -j LOG

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

In which log collection mechanism, the system or application sends log records either on the local disk or over the network.

Options
A

rule-based

B

pull-based

C

push-based

D

signature-based

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.