Which of the following attack inundates DHCP servers with fake DHCP requests toexhaust all available IP addresses?
Correct Answer: A
A DHCP Starvation Attack is a type of network attack that aims to deplete the pool of available IP addresses on the DHCP server. The attacker floods the DHCP server with fake DHCP DISCOVER messages using spoofed MAC addresses. If successful, the server will exhaust its address space, denying IP configuration to legitimate clients. This can lead to a denial of service (DoS) for new devices attempting to join the network. Additionally, the attacker may set up a rogue DHCP server to issue malicious IP configurations to clients, potentially redirecting traffic or causing further disruption1. References: The EC-Council SOC Analyst course and study materials cover various network attacks, including DHCP Starvation Attacks. These resources provide insights into the nature of these attacks, their potential impact, and strategies for prevention and mitigation213. Reference: https://www.cbtnuggets.com/blog/technology/networking/what-is-a-dhcp-starvation-attack
Question 72
The SOC team at GlobalTech has finished patching a critical vulnerability exploited during a ransomware attack. The team is now restoring 2.3 TB of encrypted data from their Veeam backup system, rebuilding 23 compromised workstations identified through SIEM logs, and re-enabling network access for the finance department after validating systems are clean. Which Incident Response phase is this?
Correct Answer: D
This activity is Recovery because it focuses on restoring systems and business operations to a normal, trusted state after the threat has been contained and eradicated. Restoring encrypted data from backups, rebuilding compromised workstations, and re-enabling network access are all recovery tasks. The key objective in recovery is to return services safely while ensuring the environment is clean and stable-hence validation steps before reconnecting systems to production networks. Containment would have occurred earlier and would include isolating affected VLANs/hosts and stopping spread. Eradication would include removing ransomware artifacts, closing persistence, patching vulnerabilities (which the scenario says has already been done), and ensuring the attacker cannot regain access. Post-incident activities occur after recovery and include lessons learned, reporting, process improvements, and control updates. From a SOC operational standpoint, recovery is often the most resource-intensive phase because it requires coordination between security, IT operations, application owners, and business units to restore systems, verify integrity, and monitor for reinfection. Because the scenario is explicitly about restore/rebuild and safe return-to-service, the correct phase is recovery.
Question 73
A health corporation is implementing a SIEM solution to improve detection and response and comply with HIPAA requirements. They need the SIEM to efficiently collect, analyze, and correlate security events from network devices, servers, and security applications, and generate timely alerts for potential HIPAA violations. Which capability is needed to meet these needs?
Correct Answer: C
To meet the stated needs-collecting, analyzing, correlating, and alerting-log management and security analytics is the core SIEM capability set. Log management covers ingestion, parsing, normalization, storage, retention, and search. Security analytics covers detection rules, correlations, behavioral analytics, alerting, and dashboards that turn raw events into actionable incidents. These functions are essential for identifying potential HIPAA violations (unauthorized access, anomalous data access, improper privilege use) and producing timely alerts and audit evidence. "Centralized SIEM implementation" is an architectural statement rather than a capability; centralization helps but doesn't describe the functions needed. "Log collection through agents" is one ingestion method and is important for coverage, but by itself it doesn't provide analysis and correlation. Threat hunting and intelligence are valuable enhancements, but the requirement described is the baseline SIEM function: manage logs and apply analytics to detect and alert. From a SOC standpoint, this also supports compliance because strong log management with tuned analytics enables both real-time incident response and retrospective investigations with reliable retention and audit trails.
Question 74
Global Bank relies heavily on Microsoft Azure to host critical banking applications and services. The SOC must ensure continuous monitoring, compliance, and real-time threat detection across Azure resources. They need a comprehensive solution to collect, analyze, and visualize telemetry from cloud resources, VMs, storage, and applications, and integrate with security tools to detect anomalies and monitor performance. Which Azure service is best suited?
Correct Answer: B
Azure Monitor is the Azure-native platform for collecting, analyzing, and visualizing telemetry across Azure resources, including metrics and logs from infrastructure, applications, and services. For SOC needs, it provides centralized observability: resource metrics, activity logs, diagnostic logs, and integration with log analytics for query and alerting. This supports both performance monitoring and security monitoring by enabling detection of unusual behaviors (unexpected spikes, anomalous access patterns) and providing dashboards and alerting to support rapid response. Azure Firewall is a network security control focused on traffic filtering and policy enforcement; it does not serve as the comprehensive telemetry collection and visualization layer for all Azure resources. Azure Policy focuses on governance and compliance enforcement by evaluating and enforcing resource configuration rules; it's important but not the main telemetry analysis solution. Azure Active Directory is the identity service (now commonly referred to as Entra ID) and is essential for authentication/authorization, but it is not the cross-resource monitoring platform. Since the question emphasizes broad telemetry collection, analysis, and visualization across Azure resources for continuous monitoring, Azure Monitor is the correct service.
Question 75
In which phase of Lockheed Martin's - Cyber Kill Chain Methodology, adversary creates a deliverable malicious payload using an exploit and a backdoor?
Newest 312-39 Exam PDF Dumps shared by BraindumpsPass.com for Helping Passing 312-39 Exam! BraindumpsPass.com now offer the updated 312-39 exam dumps, the BraindumpsPass.com 312-39 exam questions have been updated and answers have been corrected get the latest BraindumpsPass.com 312-39 pdf dumps with Exam Engine here: