EC-COUNCIL · 312-39v2 CSA v2

EC-Council 312-39v2 CSA v2 Exam Practice Questions

196 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 196 questions in this pack

Question 1

A SIEM alert is triggered due to unusual network traffic involving NetBIOS. The System log shows that “The TCP/IP NetBIOS Helper service entered the running state”. Concurrently, Event Code 4624: “An account was successfully logged on” appears for multiple machines within a short time frame. The logon type is identified as 3 (Network logon).

Which of the following security incidents is the SIEM detecting?

  1. A user connecting to shared files from multiple workstations
  2. A malware infection spreading via SMB protocol
  3. A network administrator conducting routine maintenance
  4. An attacker performing lateral movement within the network
Show answer and explanation

Correct answer: D. An attacker performing lateral movement within the network

network The indicators present, NetBIOS traffic, TCP/IP NetBIOS Helper service activation, and multiple successful Network logons (type 3) across machines in rapid succession, are characteristic of lateral movement. An attacker compromising one system uses it to authenticate across the network to other machines using the SMB/NetBIOS protocol. This pattern differs from routine user activity across multiple workstations, which would show different logon patterns and distribution, and differs from simple file access. While malware could spread via SMB, the specific focus on successful authentications and NetBIOS activation points to deliberate lateral movement rather than autonomous malware propagation.

Why the other options are wrong

  • A. Normal multi-workstation file access would not trigger sustained NetBIOS traffic alerts or show concentrated authentication events across multiple systems in rapid succession.
  • B. Malware spreading autonomously via SMB would show different infection patterns and network signatures rather than successful logon events across multiple systems.
  • C. Routine maintenance by administrators would typically be scheduled, documented, and not trigger multiple unexpected authentications flagged as anomalous by the SIEM.

Question 2

A manufacturing company is deploying a SIEM system and wants to improve both its security monitoring and regulatory compliance capabilities.

During the planning phase, the team decides to use an output-driven approach, starting with use cases that address unauthorized access to production control systems. They configure data sources and alert specific to this use case, ensuring they receive

actionable alerts without excessive false positives. After validating its success, they move on to use cases related to supply chain disruptions and malware detection.

Which of the following best describes the primary advantage of using an output-driven approach in SIEM deployment?

  1. The company can collect logs from non-critical systems.
  2. The SOC team can respond to all incidents in real time without delays.
  3. The SIEM system can automatically block all unauthorized access attempts.
  4. The company can create more complex use cases with greater scope.
Show answer and explanation

Correct answer: D. The company can create more complex use cases with greater scope.

with greater scope. An output-driven approach begins with defined, high-value use cases and builds the SIEM implementation around them, starting with unauthorized access to production control systems. After validating success, the team progressively adds more complex use cases related to supply chain disruptions and malware detection. This methodical expansion allows the organization to build increasingly sophisticated detection capabilities with validated, tuned alerting at each stage. The primary advantage is the ability to systematically create more complex use cases with greater scope as the program matures, rather than attempting to address everything simultaneously.

Why the other options are wrong

  • A. Log collection from non-critical systems is not the focus of an output-driven approach, which prioritizes high-impact use cases regardless of system criticality.
  • B. Real-time response to all incidents is an operational capability goal, not an advantage of the deployment methodology itself.
  • C. Automatic blocking of all unauthorized access is a technical control decision, not a primary advantage of using an output-driven deployment approach.

Question 3

An attacker attempts to gain unauthorized access to a secure network by repeatedly guessing login credentials. The SIEM is configured to generate an alert after detecting 10 consecutive failed login attempts within a short timeframe. However, the attacker successfully logs in on the 9th attempt, just before the threshold is reached, bypassing the alert mechanism. Security teams only become aware of the incident after detecting suspicious activity post-login, highlighting a gap in the SIEM’s detection rules.

What type of alert classification does this represent?

  1. True Positive
  2. False Positive
  3. False Negative
  4. True Negative
Show answer and explanation

Correct answer: C. False Negative

A False Negative occurs when a security event actually occurs but the detection system fails to generate an alert. In this scenario, the attacker successfully gained unauthorized access on the 9th attempt, which is a genuine security incident, but the SIEM did not alert because the threshold of 10 consecutive failed attempts was not reached. The malicious event occurred but went undetected by the alert mechanism, representing a missed detection that was only discovered through post-login investigation.

Why the other options are wrong

  • A. A True Positive would require the SIEM to correctly identify an actual attack with an alert, which did not occur in this scenario.
  • B. A False Positive is an alert triggered for activity that is not actually malicious, whereas here there was no alert generated despite actual malicious activity.
  • D. A True Negative would be correctly identifying non-malicious activity as benign, which does not apply to this unauthorized access scenario.

See all 10 free questions Get the full pack, US$39

196 practice questions for EC-Council Certified SOC Analyst v2 (CSA), exam 312-39, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 196 questions mapped to the CSA v2 exam blueprint
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A 312-39 attempt costs US$250. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 196 questions

What makes the CSA hard

CSA v2 is the Tier 1 and Tier 2 SOC analyst exam, and the v2 study material reorganised it into eight modules, with incident detection and triage and incident response carrying half the exam between them at 25% each.

Detection covers SIEM architecture and deployment, correlation rules including AI-generated rules, alert triage and dashboards, with the classic true positive, false positive, false negative questions. Response covers the incident response lifecycle, containment, eradication, recovery and post-incident documentation.

Log Management, Proactive Threat Detection and Cloud Security Operations follow, the last of which tests Microsoft Sentinel, AWS Security Hub and Google Security Command Center side by side, so it pays to keep straight which service belongs to which cloud. EC-Council’s own exam blueprint lists these eight modules without publishing official percentage weightings, and the passing score is 70%.

About the exam

312-39 v2 (Certified SOC Analyst) earns the EC-Council CSA certification. It covers security operations and management, cyber threats and indicators of compromise, log management, incident detection and triage with SIEM, proactive threat detection, incident response, forensics, and cloud security operations. There are no prerequisites with official training; self-study candidates need one year of security experience and an eligibility application.

Exam modules

  • Security Operations and Management
  • Understanding Cyber Threats, IoCs, and Attack Methodology
  • Log Management
  • Incident Detection and Triage
  • Proactive Threat Detection
  • Incident Response
  • Forensic Investigation and Malware Analysis
  • SOC for Cloud Environments

EC-Council publishes these eight modules but does not publish percentage weightings for them. 100 multiple choice questions, 180 minutes, passing score 70%, US$250 per attempt, ECC Exam Portal or Pearson VUE with remote proctoring available, certification valid for three years with EC-Council continuing education.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the EC-Council 312-39v2 CSA v2 pack?

196 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.