Official Bank 0/200

312-39 (312-39) - EC-Council Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
200 Total Questions
1
Question
A large financial institution has identified a sophisticated phishing campaign targeting employees, resulting in unauthorized access to sensitive customer data. The organization already uses a SIEM for log aggregation and alerting, alongside an EDR solution for endpoint visibility. Additionally, they have access to XDR for broader threat detection and XSOAR for security orchestration and automation. As a SOC analyst, you’ve been asked to recommend an integration strategy to improve real-time threat correlation, streamline incident response workflows, and maximize the use of existing tools. Which integration would meet these goals?
Options
A Integrate XDR with SIEM
B Integrate EDR with XSOAR
C Integrate EDR with SIEM
D Integrate XDR with XSOAR
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Which of the following Windows features is used to enable Security Auditing in Windows?
Options
A Windows Firewall
B Windows Defender
C Local Group Policy Editor
D Bitlocker
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
A manufacturing company is deploying a SIEM system and wants to improve both security monitoring and regulatory compliance. During planning, the team uses an output-driven approach, starting with use cases that address unauthorized access to production control systems. They configure data sources and alerts specific to this use case, ensuring actionable alerts without excessive false positives. After validating success, they move on to use cases related to supply chain disruptions and malware detection. What is the primary advantage of using an output-driven approach in SIEM deployment?
Options
A The company avoids the need to collect logs from non-critical systems.
B The SOC team can respond to all incidents in real time without delays.
C The SIEM system can automatically block all unauthorized access attempts.
D The company can create more complex use cases with greater scope.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Jackson & Co., a mid-sized law firm, is concerned about web-based cyber threats. The IT team implements a solution that serves as an intermediary for all HTTP and HTTPS requests. This allows the SOC to inspect, filter, and control web traffic to detect and block malicious websites, phishing attempts, and other online threats before they reach users. Which containment method is the organization using to gain visibility and control over web traffic?
Options
A Blacklisting
B Proxy servers
C Web content filtering
D Whitelisting
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
What is the process of monitoring and capturing all data packets passing through a given network using different tools?
Options
A DNS Footprinting
B Port Scanning
C Network Sniffing
D Network Scanning
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.