
ECCouncil 312-85 Certification All-in-One Exam Guide Feb-2024
Get Real 312-85 Exam Dumps [Feb-2024] Practice Tests
ECCouncil 312-85 (Certified Threat Intelligence Analyst) certification exam is an essential credential for professionals looking to acquire advanced threat intelligence skills. 312-85 exam covers a wide range of topics and requires a significant amount of preparation to be successful. Certified Threat Intelligence Analyst certification is highly respected in the industry and is recognized as a benchmark for measuring the expertise of professionals in threat intelligence analysis.
The CTIA certification exam is intended for professionals with experience in cybersecurity or related fields such as IT security, risk management, and compliance. Individuals who are seeking to advance their careers in threat intelligence or those who are looking to transition into this field can benefit from this certification. The CTIA certification exam is also suitable for individuals who are responsible for managing and leading cybersecurity teams and initiatives.
NEW QUESTION # 18
Which of the following components refers to a node in the network that routes the traffic from a workstation to external command and control server and helps in identification of installed malware in the network?
- A. Network interface card (NIC)
- B. Repeater
- C. Gateway
- D. Hub
Answer: C
NEW QUESTION # 19
A network administrator working in an ABC organization collected log files generated by a traffic monitoring system, which may not seem to have useful information, but after performing proper analysis by him, the same information can be used to detect an attack in the network.
Which of the following categories of threat information has he collected?
- A. Detection indicators
- B. Strategic reports
- C. Low-level data
- D. Advisories
Answer: A
NEW QUESTION # 20
During the process of threat intelligence analysis, John, a threat analyst, successfully extracted an indication of adversary's information, such as Modus operandi, tools, communication channels, and forensics evasion strategies used by adversaries.
Identify the type of threat intelligence analysis is performed by John.
- A. Tactical threat intelligence analysis
- B. Strategic threat intelligence analysis
- C. Technical threat intelligence analysis
- D. Operational threat intelligence analysis
Answer: A
NEW QUESTION # 21
Tracy works as a CISO in a large multinational company. She consumes threat intelligence to understand the changing trends of cyber security. She requires intelligence to understand the current business trends and make appropriate decisions regarding new technologies, security budget, improvement of processes, and staff. The intelligence helps her in minimizing business risks and protecting the new technology and business initiatives.
Identify the type of threat intelligence consumer is Tracy.
- A. Technical users
- B. Operational users
- C. Strategic users
- D. Tactical users
Answer: C
NEW QUESTION # 22
An XYZ organization hired Mr. Andrews, a threat analyst. In order to identify the threats and mitigate the effect of such threats, Mr. Andrews was asked to perform threat modeling. During the process of threat modeling, he collected important information about the treat actor and characterized the analytic behavior of the adversary that includes technological details, goals, and motives that can be useful in building a strong countermeasure.
What stage of the threat modeling is Mr. Andrews currently in?
- A. System modeling
- B. Threat determination and identification
- C. Threat profiling and attribution
- D. Threat ranking
Answer: C
NEW QUESTION # 23
A team of threat intelligence analysts is performing threat analysis on malware, and each of them has come up with their own theory and evidence to support their theory on a given malware.
Now, to identify the most consistent theory out of all the theories, which of the following analytic processes must threat intelligence manager use?
- A. Analysis of competing hypotheses (ACH)
- B. Threat modelling
- C. Automated technical analysis
- D. Application decomposition and analysis (ADA)
Answer: A
NEW QUESTION # 24
Enrage Tech Company hired Enrique, a security analyst, for performing threat intelligence analysis. While performing data collection process, he used a counterintelligence mechanism where a recursive DNS server is employed to perform interserver DNS communication and when a request is generated from any name server to the recursive DNS server, the recursive DNS servers log the responses that are received. Then it replicates the logged data and stores the data in the central database. Using these logs, he analyzed the malicious attempts that took place over DNS infrastructure.
Which of the following cyber counterintelligence (CCI) gathering technique has Enrique used for data collection?
- A. Data collection through dynamic DNS (DDNS)
- B. Data collection through DNS zone transfer
- C. Data collection through passive DNS monitoring
- D. Data collection through DNS interrogation
Answer: D
NEW QUESTION # 25
In a team of threat analysts, two individuals were competing over projecting their own hypotheses on a given malware. However, to find logical proofs to confirm their hypotheses, the threat intelligence manager used a de-biasing strategy that involves learning strategic decision making in the circumstances comprising multistep interactions with numerous representatives, either having or without any perfect relevant information.
Which of the following de-biasing strategies the threat intelligence manager used to confirm their hypotheses?
- A. Cognitive psychology
- B. Game theory
- C. Machine learning
- D. Decision theory
Answer: D
NEW QUESTION # 26
Kathy wants to ensure that she shares threat intelligence containing sensitive information with the appropriate audience. Hence, she used traffic light protocol (TLP).
Which TLP color would you signify that information should be shared only within a particular community?
- A. Amber
- B. Green
- C. Red
- D. White
Answer: B
NEW QUESTION # 27
Alice, an analyst, shared information with security operation managers and network operations center (NOC) staff for protecting the organizational resources against various threats. Information shared by Alice was highly technical and include threat actor TTPs, malware campaigns, tools used by threat actors, and so on.
Which of the following types of threat intelligence was shared by Alice?
- A. Strategic threat intelligence
- B. Tactical threat intelligence
- C. Operational threat intelligence
- D. Technical threat intelligence
Answer: B
NEW QUESTION # 28
Alison, an analyst in an XYZ organization, wants to retrieve information about a company's website from the time of its inception as well as the removed information from the target website.
What should Alison do to get the information he needs.
- A. Alison should use https://archive.org to extract the required website information.
- B. Alison should run the Web Data Extractor tool to extract the required website information.
- C. Alison should use SmartWhois to extract the required website information.
- D. Alison should recover cached pages of the website from the Google search engine cache to extract the required website information.
Answer: B
NEW QUESTION # 29
What is the correct sequence of steps involved in scheduling a threat intelligence program?
1. Review the project charter
2. Identify all deliverables
3. Identify the sequence of activities
4. Identify task dependencies
5. Develop the final schedule
6. Estimate duration of each activity
7. Identify and estimate resources for all activities
8. Define all activities
9. Build a work breakdown structure (WBS)
- A. 1-->9-->2-->8-->3-->7-->4-->6-->5
- B. 1-->2-->3-->4-->5-->6-->7-->8-->9
- C. 3-->4-->5-->2-->1-->9-->8-->7-->6
- D. 1-->2-->3-->4-->5-->6-->9-->8-->7
Answer: A
NEW QUESTION # 30
Daniel is a professional hacker whose aim is to attack a system to steal data and money for profit. He performs hacking to obtain confidential data such as social security numbers, personally identifiable information (PII) of an employee, and credit card information. After obtaining confidential data, he further sells the information on the black market to make money.
Daniel comes under which of the following types of threat actor.
- A. Organized hackers
- B. State-sponsored hackers
- C. Insider threat
- D. Industrial spies
Answer: A
NEW QUESTION # 31
In which of the following storage architecture is the data stored in a localized system, server, or storage hardware and capable of storing a limited amount of data in its database and locally available for data usage?
- A. Cloud storage
- B. Distributed storage
- C. Centralized storage
- D. Object-based storage
Answer: D
NEW QUESTION # 32
Alice, a threat intelligence analyst at HiTech Cyber Solutions, wants to gather information for identifying emerging threats to the organization and implement essential techniques to prevent their systems and networks from such attacks. Alice is searching for online sources to obtain information such as the method used to launch an attack, and techniques and tools used to perform an attack and the procedures followed for covering the tracks after an attack.
Which of the following online sources should Alice use to gather such information?
- A. Financial services
- B. Social network settings
- C. Hacking forums
- D. Job sites
Answer: C
NEW QUESTION # 33
Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information from a variety of sources. He wants to use this information to develop security policies to enhance the overall security posture of his organization.
Which of the following sharing platforms should be used by Kim?
- A. Cuckoo sandbox
- B. Blueliv threat exchange network
- C. PortDroid network analysis
- D. OmniPeek
Answer: B
NEW QUESTION # 34
Andrews and Sons Corp. has decided to share threat information among sharing partners. Garry, a threat analyst, working in Andrews and Sons Corp., has asked to follow a trust model necessary to establish trust between sharing partners. In the trust model used by him, the first organization makes use of a body of evidence in a second organization, and the level of trust between two organizations depends on the degree and quality of evidence provided by the first organization.
Which of the following types of trust model is used by Garry to establish the trust?
- A. Mandated trust
- B. Direct historical trust
- C. Validated trust
- D. Mediated trust
Answer: C
NEW QUESTION # 35
An organization suffered many major attacks and lost critical information, such as employee records, and financial information. Therefore, the management decides to hire a threat analyst to extract the strategic threat intelligence that provides high-level information regarding current cyber-security posture, threats, details on the financial impact of various cyber-activities, and so on.
Which of the following sources will help the analyst to collect the required intelligence?
- A. OSINT, CTI vendors, ISAO/ISACs
- B. Human, social media, chat rooms
- C. Active campaigns, attacks on other organizations, data feeds from external third parties
- D. Campaign reports, malware, incident reports, attack group reports, human intelligence
Answer: A
NEW QUESTION # 36
Steve works as an analyst in a UK-based firm. He was asked to perform network monitoring to find any evidence of compromise. During the network monitoring, he came to know that there are multiple logins from different locations in a short time span. Moreover, he also observed certain irregular log in patterns from locations where the organization does not have business relations. This resembles that somebody is trying to steal confidential information.
Which of the following key indicators of compromise does this scenario present?
- A. Unusual outbound network traffic
- B. Geographical anomalies
- C. Unusual activity through privileged user account
- D. Unexpected patching of systems
Answer: B
NEW QUESTION # 37
SecurityTech Inc. is developing a TI plan where it can drive more advantages in less funds. In the process of selecting a TI platform, it wants to incorporate a feature that ranks elements such as intelligence sources, threat actors, attacks, and digital assets of the organization, so that it can put in more funds toward the resources which are critical for the organization's security.
Which of the following key features should SecurityTech Inc. consider in their TI plan for selecting the TI platform?
- A. Workflow
- B. Scoring
- C. Open
- D. Search
Answer: B
NEW QUESTION # 38
An analyst is conducting threat intelligence analysis in a client organization, and during the information gathering process, he gathered information from the publicly available sources and analyzed to obtain a rich useful form of intelligence. The information source that he used is primarily used for national security, law enforcement, and for collecting intelligence required for business or strategic decision making.
Which of the following sources of intelligence did the analyst use to collect information?
- A. ISAC
- B. SIGINT
- C. OSINT
- D. OPSEC
Answer: C
NEW QUESTION # 39
John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques.
What phase of the advanced persistent threat lifecycle is John currently in?
- A. Search and exfiltration
- B. Expansion
- C. Persistence
- D. Initial intrusion
Answer: B
NEW QUESTION # 40
An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery locations in the rapidly changing network of compromised bots. In this particular technique, a single domain name consists of multiple IP addresses.
Which of the following technique is used by the attacker?
- A. DNS zone transfer
- B. Dynamic DNS
- C. Fast-Flux DNS
- D. DNS interrogation
Answer: C
NEW QUESTION # 41
......
The CTIA certification exam is a vendor-neutral certification, meaning that it is not tied to any specific technology or platform. This makes it an ideal certification for cybersecurity professionals who are looking to enhance their skills and knowledge in threat intelligence without being limited to a specific vendor or product. It is also a valuable certification for organizations looking to hire skilled threat intelligence professionals who can help them stay ahead of emerging security threats.
Last 312-85 practice test reviews: Practice Test ECCouncil dumps: https://www.testkingpdf.com/312-85-testking-pdf-torrent.html
Try 312-85 Free Now! Real Exam Question Answers: https://drive.google.com/open?id=1DYIHDiU9xgJLztuNO8vUQEm_a_0ZrkeD

