Go Back on 312-39 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

312-39 Practice Test


Page 4 out of 21 Pages

Where will you find the reputation IP database, if you want to monitor traffic from known bad IP reputation using OSSIM SIEM?


A.

/etc/ossim/reputation


B.

/etc/ossim/siem/server/reputation/data


C.

/etc/siem/ossim/server/reputation.data


D.

/etc/ossim/server/reputation.data





A.
  

/etc/ossim/reputation



According to the forensics investigation process, what is the next step carried out right after collecting the evidence?


A.

Create a Chain of Custody Document


B.

Send it to the nearby police station


C.

Set a Forensic lab


D.

Call Organizational Disciplinary Team





A.
  

Create a Chain of Custody Document



Which of the following command is used to enable logging in iptables?


A.

$ iptables -B INPUT -j LOG


B.

$ iptables -A OUTPUT -j LOG


C.

$ iptables -A INPUT -j LOG


D.

$ iptables -B OUTPUT -j LOG





B.
  

$ iptables -A OUTPUT -j LOG



Reference: https://tecadmin.net/enable-logging-in-iptables-on-linux/

Peter, a SOC analyst with Spade Systems, is monitoring and analyzing the router logs of the company and wanted to check the logs that are generated by access control list numbered 210.
What filter should Peter add to the 'show logging' command to get the required output?


A.

show logging | access 210


B.

show logging | forward 210


C.

show logging | include 210


D.

show logging | route 210





C.
  

show logging | include 210



What does the HTTP status codes 1XX represents?


A.

Informational messag


B.

Client error


C.

Success


D.

Redirection





A.
  

Informational messag



Reference:
https://en.wikipedia.org/wiki/List_of_HTTP_status_codes#:~:text=1xx-informational%
20response-–-the-request,syntax-or-cannot-be-fulfilled


Page 4 out of 21 Pages
Previous