
Latest [Nov 03, 2021] 312-85 Exam with Accurate Certified Threat Intelligence Analyst PDF Questions
Take a Leap Forward in Your Career by Earning ECCouncil 50 Questions
ECCouncil 312-85 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
| Topic 11 |
|
| Topic 12 |
|
| Topic 13 |
|
NEW QUESTION 12
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?
- A. Advanced persistent attack
- B. Zero-day attack
- C. Distributed network attack
- D. Active online attack
Answer: B
NEW QUESTION 13
Alice, a threat intelligence analyst at HiTech Cyber Solutions, wants to gather information for identifying emerging threats to the organization and implement essential techniques to prevent their systems and networks from such attacks. Alice is searching for online sources to obtain information such as the method used to launch an attack, and techniques and tools used to perform an attack and the procedures followed for covering the tracks after an attack.
Which of the following online sources should Alice use to gather such information?
- A. Social network settings
- B. Job sites
- C. Financial services
- D. Hacking forums
Answer: D
NEW QUESTION 14
An XYZ organization hired Mr. Andrews, a threat analyst. In order to identify the threats and mitigate the effect of such threats, Mr. Andrews was asked to perform threat modeling. During the process of threat modeling, he collected important information about the treat actor and characterized the analytic behavior of the adversary that includes technological details, goals, and motives that can be useful in building a strong countermeasure.
What stage of the threat modeling is Mr. Andrews currently in?
- A. Threat profiling and attribution
- B. Threat determination and identification
- C. System modeling
- D. Threat ranking
Answer: A
NEW QUESTION 15
Cybersol Technologies initiated a cyber-threat intelligence program with a team of threat intelligence analysts. During the process, the analysts started converting the raw data into useful information by applying various techniques, such as machine-based techniques, and statistical methods.
In which of the following phases of the threat intelligence lifecycle is the threat intelligence team currently working?
- A. Processing and exploitation
- B. Dissemination and integration
- C. Planning and direction
- D. Analysis and production
Answer: B
NEW QUESTION 16
An analyst is conducting threat intelligence analysis in a client organization, and during the information gathering process, he gathered information from the publicly available sources and analyzed to obtain a rich useful form of intelligence. The information source that he used is primarily used for national security, law enforcement, and for collecting intelligence required for business or strategic decision making.
Which of the following sources of intelligence did the analyst use to collect information?
- A. SIGINT
- B. OSINT
- C. OPSEC
- D. ISAC
Answer: B
NEW QUESTION 17
Alice, an analyst, shared information with security operation managers and network operations center (NOC) staff for protecting the organizational resources against various threats. Information shared by Alice was highly technical and include threat actor TTPs, malware campaigns, tools used by threat actors, and so on.
Which of the following types of threat intelligence was shared by Alice?
- A. Operational threat intelligence
- B. Technical threat intelligence
- C. Strategic threat intelligence
- D. Tactical threat intelligence
Answer: B
NEW QUESTION 18
Which of the following types of threat attribution deals with the identification of the specific person, society, or a country sponsoring a well-planned and executed intrusion or attack over its target?
- A. Campaign attribution
- B. True attribution
- C. Intrusion-set attribution
- D. Nation-state attribution
Answer: B
NEW QUESTION 19
Which of the following characteristics of APT refers to numerous attempts done by the attacker to gain entry to the target's network?
- A. Timeliness
- B. Risk tolerance
- C. Attack origination points
- D. Multiphased
Answer: C
NEW QUESTION 20
What is the correct sequence of steps involved in scheduling a threat intelligence program?
1. Review the project charter
2. Identify all deliverables
3. Identify the sequence of activities
4. Identify task dependencies
5. Develop the final schedule
6. Estimate duration of each activity
7. Identify and estimate resources for all activities
8. Define all activities
9. Build a work breakdown structure (WBS)
- A. 3-->4-->5-->2-->1-->9-->8-->7-->6
- B. 1-->2-->3-->4-->5-->6-->7-->8-->9
- C. 1-->2-->3-->4-->5-->6-->9-->8-->7
- D. 1-->9-->2-->8-->3-->7-->4-->6-->5
Answer: D
NEW QUESTION 21
John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques.
What phase of the advanced persistent threat lifecycle is John currently in?
- A. Search and exfiltration
- B. Expansion
- C. Persistence
- D. Initial intrusion
Answer: B
NEW QUESTION 22
Bob, a threat analyst, works in an organization named TechTop. He was asked to collect intelligence to fulfil the needs and requirements of the Red Tam present within the organization.
Which of the following are the needs of a RedTeam?
- A. Intelligence extracted latest attacks analysis on similar organizations, which includes details about latest threats and TTPs
- B. Intelligence on latest vulnerabilities, threat actors, and their tactics, techniques, and procedures (TTPs)
- C. Intelligence related to increased attacks targeting a particular software or operating system vulnerability
- D. Intelligence that reveals risks related to various strategic business decisions
Answer: B
NEW QUESTION 23
Enrage Tech Company hired Enrique, a security analyst, for performing threat intelligence analysis. While performing data collection process, he used a counterintelligence mechanism where a recursive DNS server is employed to perform interserver DNS communication and when a request is generated from any name server to the recursive DNS server, the recursive DNS servers log the responses that are received. Then it replicates the logged data and stores the data in the central database. Using these logs, he analyzed the malicious attempts that took place over DNS infrastructure.
Which of the following cyber counterintelligence (CCI) gathering technique has Enrique used for data collection?
- A. Data collection through DNS zone transfer
- B. Data collection through passive DNS monitoring
- C. Data collection through DNS interrogation
- D. Data collection through dynamic DNS (DDNS)
Answer: C
NEW QUESTION 24
Walter and Sons Company has faced major cyber attacks and lost confidential dat a. The company has decided to concentrate more on the security rather than other resources. Therefore, they hired Alice, a threat analyst, to perform data analysis. Alice was asked to perform qualitative data analysis to extract useful information from collected bulk data.
Which of the following techniques will help Alice to perform qualitative data analysis?
- A. Numerical calculations, statistical modeling, measurement, research, and so on.
- B. Finding links between data and discover threat-related information
- C. Regression analysis, variance analysis, and so on
- D. Brainstorming, interviewing, SWOT analysis, Delphi technique, and so on
Answer: D
NEW QUESTION 25
Jian is a member of the security team at Trinity, Inc. He was conducting a real-time assessment of system activities in order to acquire threat intelligence feeds. He acquired feeds from sources like honeynets, P2P monitoring. infrastructure, and application logs.
Which of the following categories of threat intelligence feed was acquired by Jian?
- A. CSV data feeds
- B. Internal intelligence feeds
- C. External intelligence feeds
- D. Proactive surveillance feeds
Answer: B
NEW QUESTION 26
H&P, Inc. is a small-scale organization that has decided to outsource the network security monitoring due to lack of resources in the organization. They are looking for the options where they can directly incorporate threat intelligence into their existing network defense solutions.
Which of the following is the most cost-effective methods the organization can employ?
- A. Look for an individual within the organization
- B. Recruit data management solution provider
- C. Recruit the right talent
- D. Recruit managed security service providers (MSSP)
Answer: D
NEW QUESTION 27
Michael, a threat analyst, works in an organization named TechTop, was asked to conduct a cyber-threat intelligence analysis. After obtaining information regarding threats, he has started analyzing the information and understanding the nature of the threats.
What stage of the cyber-threat intelligence is Michael currently in?
- A. Known knowns
- B. Unknown unknowns
- C. Unknowns unknown
- D. Known unknowns
Answer: D
NEW QUESTION 28
Alison, an analyst in an XYZ organization, wants to retrieve information about a company's website from the time of its inception as well as the removed information from the target website.
What should Alison do to get the information he needs.
- A. Alison should recover cached pages of the website from the Google search engine cache to extract the required website information.
- B. Alison should run the Web Data Extractor tool to extract the required website information.
- C. Alison should use https://archive.org to extract the required website information.
- D. Alison should use SmartWhois to extract the required website information.
Answer: B
NEW QUESTION 29
A threat analyst obtains an intelligence related to a threat, where the data is sent in the form of a connection request from a remote host to the server. From this data, he obtains only the IP address of the source and destination but no contextual information. While processing this data, he obtains contextual information stating that multiple connection requests from different geo-locations are received by the server within a short time span, and as a result, the server is stressed and gradually its performance has reduced. He further performed analysis on the information based on the past and present experience and concludes the attack experienced by the client organization.
Which of the following attacks is performed on the client organization?
- A. DHCP attacks
- B. MAC spoofing attack
- C. Distributed Denial-of-Service (DDoS) attack
- D. Bandwidth attack
Answer: C
NEW QUESTION 30
Tracy works as a CISO in a large multinational company. She consumes threat intelligence to understand the changing trends of cyber security. She requires intelligence to understand the current business trends and make appropriate decisions regarding new technologies, security budget, improvement of processes, and staff. The intelligence helps her in minimizing business risks and protecting the new technology and business initiatives.
Identify the type of threat intelligence consumer is Tracy.
- A. Tactical users
- B. Strategic users
- C. Technical users
- D. Operational users
Answer: B
NEW QUESTION 31
Daniel is a professional hacker whose aim is to attack a system to steal data and money for profit. He performs hacking to obtain confidential data such as social security numbers, personally identifiable information (PII) of an employee, and credit card information. After obtaining confidential data, he further sells the information on the black market to make money.
Daniel comes under which of the following types of threat actor.
- A. Organized hackers
- B. State-sponsored hackers
- C. Insider threat
- D. Industrial spies
Answer: A
NEW QUESTION 32
......
Authentic Best resources for 312-85 Online Practice Exam: https://www.test4cram.com/312-85_real-exam-dumps.html
Practice To 312-85 - Test4Cram Remarkable Practice On your Certified Threat Intelligence Analyst Exam: https://drive.google.com/open?id=1ahldysWiH2vO-cL-X9i8X-0UhJwVtKWB