312-85 Exam Questions
50 real 312-85 exam questions with expert-verified answers and explanations. Page 1 of 1.
- Question #1Introduction to Threat Intelligence
Which of the following characteristics of APT refers to numerous attempts done by the attacker to gain entry to the target's network?
APT characteristicsAttack vectorsThreat actorsEntry point diversification - Question #2Threat Intelligence Analysis
Lizzy, an analyst, wants to recognize the level of risks to the organization so as to plan countermeasures against cyber attacks. She used a threat modelling methodology where she...
OCTAVE methodologythreat modelingrisk assessmentasset-based approach - Question #3Threat Intelligence Analysis
Which of the following types of threat attribution deals with the identification of the specific person, society, or a country sponsoring a well-planned and executed intrusion or a...
threat attributionsponsor identificationattribution typesthreat actor analysis - Question #4Threat Intelligence Analysis
In a team of threat analysts, two individuals were competing over projecting their own hypotheses on a given malware. However, to find logical proofs to confirm their hypotheses, t...
Game TheoryDe-biasingThreat AnalysisDecision Making - Question #5Cyber Threat Intelligence Lifecycle
Cybersol Technologies initiated a cyber-threat intelligence program with a team of threat intelligence analysts. During the process, the analysts started converting the raw data in...
Processing and ExploitationAnalytical TechniquesThreat Intelligence LifecycleData Conversion - Question #6Cyber Threat Intelligence Lifecycle
Joe works as a threat intelligence analyst with Xsecurity Inc. He is assessing the TI program by comparing the project results with the original objectives by reviewing project cha...
Gap AnalysisProgram AssessmentDeliverable QualityTI Program Evaluation - Question #7Threat Intelligence Reporting and Dissemination
An analyst wants to disseminate the information effectively so that the consumers can acquire and benefit out of the intelligence. Which of the following criteria must an analyst c...
Intelligence DisseminationInformation PresentationConsumer CommunicationIntelligence Reporting - Question #8Introduction to Threat Intelligence
Tracy works as a CISO in a large multinational company. She consumes threat intelligence to understand the changing trends of cyber security. She requires intelligence to understan...
Threat Intelligence Consumer TypesStrategic Threat IntelligenceExecutive Decision-MakingCISO Role - Question #9Threat Intelligence Feeds and Sources
An organization suffered many major attacks and lost critical information, such as employee records, and financial information. Therefore, the management decides to hire a threat a...
threat intelligence sourcesOSINTCTI vendorsISAO/ISACs - Question #10Threat Intelligence Feeds and Sources
A network administrator working in an ABC organization collected log files generated by a traffic monitoring system, which may not seem to have useful information, but after perfor...
Low-level dataRaw log analysisThreat information categoriesTraffic monitoring sources - Question #11Threat Intelligence Tools and Platforms
Sam works as an analyst in an organization named InfoTech Security. He was asked to collect information from various threat intelligence sources. In meeting the deadline, he forgot...
source verificationdata qualitythreat intelligence platformsdata validation - Question #12Introduction to Threat Intelligence
Alice, an analyst, shared information with security operation managers and network operations center (NOC) staff for protecting the organizational resources against various threats...
tactical threat intelligenceTTPsthreat actor toolsSOC operations - Question #13Threat Intelligence Analysis
An XYZ organization hired Mr. Andrews, a threat analyst. In order to identify the threats and mitigate the effect of such threats, Mr. Andrews was asked to perform threat modeling....
threat modelingthreat profilingthreat attributionadversary characterization - Question #14Threat Intelligence Tools and Platforms
Alison, an analyst in an XYZ organization, wants to retrieve information about a company's website from the time of its inception as well as the removed information from the target...
historical-web-datapassive-reconnaissancewayback-machineosint-sources - Question #15Threat Intelligence Feeds and Sources
In which of the following forms of bulk data collection are large amounts of data first collected from multiple sources in multiple formats and then processed to achieve threat int...
bulk data collectionunstructured datamultiple sourcesdata formats - Question #16Threat Intelligence Tools and Platforms
In which of the following storage architecture is the data stored in a localized system, server, or storage hardware and capable of storing a limited amount of data in its database...
Centralized StorageStorage ArchitectureData LocalizationInfrastructure - Question #17Introduction to Threat Intelligence
ABC is a well-established cyber-security company in the United States. The organization implemented the automation of tasks such as data enrichment and indicator aggregation. They...
Threat Intelligence Maturity ModelCTI Capability ProgressionReactive vs Proactive DetectionThreat Intelligence Automation - Question #18Threat Intelligence Feeds and Sources
Alice, a threat intelligence analyst at HiTech Cyber Solutions, wants to gather information for identifying emerging threats to the organization and implement essential techniques...
Threat Intelligence SourcesHacking ForumsAttack IntelligenceInformation Gathering - Question #19Cyber Threat Intelligence Lifecycle
Karry, a threat analyst at an XYZ organization, is performing threat intelligence analysis. During the data collection phase, he used a data collection method that involves no part...
data collection methodspassive data collectionthreat intelligence lifecycleobservation-based analysis - Question #20Threat Intelligence Feeds and Sources
Sarah is a security operations center (SOC) analyst working at JW Williams and Sons organization based in Chicago. As a part of security operations, she contacts information provid...
threat intelligence sourcesthreat indicatorscomprehensive cyber intelligenceintelligence sharing - Question #21Threat Intelligence Analysis
Walter and Sons Company has faced major cyber attacks and lost confidential data. The company has decided to concentrate more on the security rather than other resources. Therefore...
qualitative analysisdata analysis techniquesthreat analysis methodsintelligence analysis - Question #22Threat Intelligence Feeds and Sources
An analyst is conducting threat intelligence analysis in a client organization, and during the information gathering process, he gathered information from the publicly available so...
OSINTIntelligence SourcesThreat Intelligence CollectionPublic Data - Question #23Threat Intelligence Analysis
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?
zero-day attackvulnerability exploitationattack vectorspatch management - Question #24Threat Intelligence Tools and Platforms
H&P, Inc. is a small-scale organization that has decided to outsource the network security monitoring due to lack of resources in the organization. They are looking for the options...
Threat Intelligence IntegrationManaged Security ServicesCost-EffectivenessOutsourcing Models - Question #25Cyber Threat Intelligence Lifecycle
Henry. a threat intelligence analyst at ABC Inc., is working on a threat intelligence program. He was assigned to work on establishing criteria for prioritization of intelligence n...
Threat Intelligence PrioritizationIntelligence RequirementsRisk/Impact AssessmentThreat Analysis - Question #26Threat Intelligence Tools and Platforms
Tim is working as an analyst in an ABC organization. His organization had been facing many challenges in converting the raw threat intelligence data into meaningful contextual info...
Threat Intelligence FrameworksData ReductionData FilteringAutomated Analysis - Question #27Threat Intelligence Analysis
In terms conducting data correlation using statistical data analysis, which data correlation technique is a nonparametric analysis, which measures the degree of relationship betwee...
data correlationnonparametric analysisSpearman's rank correlationstatistical methods - Question #28Introduction to Threat Intelligence
Daniel is a professional hacker whose aim is to attack a system to steal data and money for profit. He performs hacking to obtain confidential data such as social security numbers,...
threat actor typescybercrimeorganized crimethreat classification - Question #29Threat Intelligence Analysis
An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery locations in the rapidly changing network of compromised bots. In this particular t...
Fast-Flux DNSDNS evasionBotnet C&CMalware infrastructure - Question #30Threat Intelligence Reporting and Dissemination
Kathy wants to ensure that she shares threat intelligence containing sensitive information with the appropriate audience. Hence, she used traffic light protocol (TLP). Which TLP co...
Traffic Light ProtocolTLP ColorsThreat Intelligence SharingInformation Dissemination - Question #31Threat Intelligence Feeds and Sources
Moses, a threat intelligence analyst at InfoTec Inc., wants to find crucial information about the potential threats the organization is facing by using advanced Google search opera...
Google dorksOSINTdomain spoofingphishing detection - Question #32Threat Intelligence Analysis
A team of threat intelligence analysts is performing threat analysis on malware, and each of them has come up with their own theory and evidence to support their theory on a given...
Analysis of Competing HypothesesThreat AnalysisMalware AssessmentAnalytical Methodology - Question #33Threat Intelligence Analysis
Miley, an analyst, wants to reduce the amount of collected data and make the storing and sharing process easy. She uses filtering, tagging, and queuing technique to sort out the re...
Data normalizationData structuringUnstructured data processingData organization - Question #34Introduction to Threat Intelligence
Bob, a threat analyst, works in an organization named TechTop. He was asked to collect intelligence to fulfil the needs and requirements of the Red Tam present within the organizat...
Red Team intelligence needsThreat intelligence typesTTPsVulnerability intelligence - Question #35Threat Intelligence Feeds and Sources
Jian is a member of the security team at Trinity, Inc. He was conducting a real-time assessment of system activities in order to acquire threat intelligence feeds. He acquired feed...
Internal intelligence feedsThreat intelligence sourcesHoneynetsSystem monitoring - Question #36Threat Intelligence Analysis
Which of the following components refers to a node in the network that routes the traffic from a workstation to external command and control server and helps in identification of i...
Network ComponentsCommand and Control (C2)Malware DetectionGateway Functionality - Question #37Cyber Threat Intelligence Lifecycle
What is the correct sequence of steps involved in scheduling a threat intelligence program? 1. Review the project charter 2. Identify all deliverables 3. Identify the sequence of a...
project schedulingWBSactivity sequencingtask dependencies - Question #38Threat Intelligence Tools and Platforms
Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information from a variety of sources. He wants to use this information to develop secur...
Threat Intelligence SharingIntelligence Exchange PlatformsThreat Feeds & SourcesInformation Dissemination - Question #39Threat Intelligence Analysis
During the process of threat intelligence analysis, John, a threat analyst, successfully extracted an indication of adversary's information, such as Modus operandi, tools, communic...
Tactical threat intelligenceAdversary tools and techniquesModus operandiForensic evasion - Question #40Threat Intelligence Tools and Platforms
SecurityTech Inc. is developing a TI plan where it can drive more advantages in less funds. In the process of selecting a TI platform, it wants to incorporate a feature that ranks...
TI Platform SelectionRisk ScoringResource PrioritizationThreat Assessment - Question #41Threat Intelligence Analysis
Mr. Bob, a threat analyst, is performing analysis of competing hypotheses (ACH). He has reached to a stage where he is required to apply his analysis skills effectively to reject a...
Analysis of Competing HypothesesACH MatrixHypothesis EvaluationEvidence Analysis - Question #42Threat Intelligence Tools and Platforms
Tyrion, a professional hacker, is targeting an organization to steal confidential information. He wants to perform website footprinting to obtain the following information, which i...
website footprintingHTTP headersBurp Suiteweb server reconnaissance - Question #43Cyber Threat Intelligence Lifecycle
Michael, a threat analyst, works in an organization named TechTop, was asked to conduct a cyber- threat intelligence analysis. After obtaining information regarding threats, he has...
CTI lifecycle stagesintelligence analysisthreat analysis phaseknown unknowns - Question #44Threat Intelligence Feeds and Sources
Enrage Tech Company hired Enrique, a security analyst, for performing threat intelligence analysis. While performing data collection process, he used a counterintelligence mechanis...
DNS monitoringthreat intelligence sourcesDNS logscounterintelligence - Question #45Threat Intelligence Analysis
John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain adm...
APT lifecycle phasesLateral movementPrivilege escalationExpansion - Question #46Threat Intelligence Analysis
Jim works as a security analyst in a large multinational company. Recently, a group of hackers penetrated into their organizational network and used a data staging technique to col...
data exfiltration detectionnetwork traffic monitoringfile integrity monitoringevent log analysis - Question #47Threat Intelligence Reporting and Dissemination
Andrews and Sons Corp. has decided to share threat information among sharing partners. Garry, a threat analyst, working in Andrews and Sons Corp., has asked to follow a trust model...
trust modelsevidence validationthreat intelligence sharingpartner collaboration - Question #48Threat Intelligence Analysis
A threat analyst obtains an intelligence related to a threat, where the data is sent in the form of a connection request from a remote host to the server. From this data, he obtain...
DDoS attacksAttack identificationThreat analysisNetwork attacks - Question #49Cyber Threat Intelligence Lifecycle
Jame, a professional hacker, is trying to hack the confidential information of a target organization. He identified the vulnerabilities in the target system and created a tailored...
Cyber Kill ChainWeaponization PhaseMalware PayloadAttack Methodology - Question #50Threat Intelligence Analysis
Steve works as an analyst in a UK-based firm. He was asked to perform network monitoring to find any evidence of compromise. During the network monitoring, he came to know that the...
indicators of compromisegeographical anomaliesnetwork monitoringlogin patterns