nerdexam
EC-Council

312-85 · Question #32

A team of threat intelligence analysts is performing threat analysis on malware, and each of them has come up with their own theory and evidence to support their theory on a given malware. Now, to…

The correct answer is C. Analysis of competing hypotheses (ACH). Analysis of Competing Hypotheses (ACH) is a structured analytic technique specifically designed for evaluating multiple competing explanations against available evidence - making it the ideal process when multiple analysts have proposed different theories about the same…

Threat Intelligence Analysis

Question

A team of threat intelligence analysts is performing threat analysis on malware, and each of them has come up with their own theory and evidence to support their theory on a given malware. Now, to identify the most consistent theory out of all the theories, which of the following analytic processes must threat intelligence manager use?

Options

  • AThreat modelling
  • BApplication decomposition and analysis (ADA)
  • CAnalysis of competing hypotheses (ACH)
  • DAutomated technical analysis

How the community answered

(27 responses)
  • A
    11% (3)
  • B
    4% (1)
  • C
    81% (22)
  • D
    4% (1)

Explanation

Analysis of Competing Hypotheses (ACH) is a structured analytic technique specifically designed for evaluating multiple competing explanations against available evidence - making it the ideal process when multiple analysts have proposed different theories about the same malware. ACH systematically scores each hypothesis against all evidence, helping identify which theory is most consistent with the data while minimizing cognitive bias.

Why the distractors are wrong:

  • A (Threat Modelling): Threat modelling identifies attack surfaces and potential vulnerabilities in systems - it's a proactive design-phase process, not a method for adjudicating between competing analyst theories.
  • B (Application Decomposition and Analysis): ADA breaks down an application into its components to understand attack surfaces; it's a technical dissection method, not an analytical framework for comparing hypotheses.
  • D (Automated Technical Analysis): This refers to tool-based malware analysis (sandboxing, static/dynamic analysis) - it generates evidence but doesn't resolve disagreements between competing human interpretations of that evidence.

Memory tip: Think of ACH as a "debate scorecard" - when analysts compete with their theories, you use Competing Hypotheses analysis. The word "competing" in the scenario ("each has their own theory") maps directly to the "C" in ACH.

Topics

#Analysis of Competing Hypotheses#Threat Analysis#Malware Assessment#Analytical Methodology

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice