Certification Practice Test | PDF Questions | Actual Questions | Test Engine | Pass4Sure
312-85 : Certified Threat Intelligence Analyst (C|TIA) Exam

EC-Council 312-85 Questions & Answers
Full Version: 281 Q&A
Latest 312-85 Practice Tests with Actual Questions
Get Complete pool of questions with Premium PDF and Test Engine
Exam Code : 312-85
Exam Name : Certified Threat Intelligence Analyst (C|TIA)
Vendor Name :
"EC-COUNCIL"
312-85 Dumps
312-85 Braindumps
312-85 Real Questions
312-85 Practice Test
312-85 Actual Questions
killexams.com EC-COUNCIL 312-85
Certified Threat Intelligence Analyst (C|TIA)
https://killexams.com/pass4sure/exam-detail/312-85
Question: 1
Build a work breakdown structure (WBS) A. 1-->9-->2-->8-->3-->7-->4-->6-->5
B. 3-->4-->5-->2-->1-->9-->8-->7-->6
C. 1-->2-->3-->4-->5-->6-->9-->8-->7
D. 1-->2-->3-->4-->5-->6-->7-->8-->9
Answer: A
Question: 2
SecurityTech Inc. is developing a TI plan where it can drive more advantages in less funds. In the process of selecting a TI platform, it wants to incorporate a feature that ranks elements such as intelligence sources, threat actors, attacks, and digital assets of the organization, so that it can put in more funds toward the resources which are critical for the organizationâs security.
Which of the following key features should SecurityTech Inc. consider in their TI plan for selecting the TI platform?
Search
Open
Workflow
Scoring
Answer: D
Question: 3
Henry. a threat intelligence analyst at ABC Inc., is working on a threat intelligence program. He was assigned to work on establishing criteria for prioritization of intelligence needs and requirements.
Which of the following considerations must be employed by Henry to prioritize intelligence requirements?
Understand frequency and impact of a threat
Understand data reliability
Develop a collection plan
Produce actionable data
Answer: A
Question: 4
Tim is working as an analyst in an ABC organization. His organization had been facing many challenges in converting the raw threat intelligence data into meaningful contextual information. After inspection, he found that it was due to noise obtained from misrepresentation of data from huge data collections. Hence, it is important to clean the data before performing data analysis using techniques such as data reduction. He needs to choose an appropriate threat intelligence framework that automatically performs data collection, filtering, and analysis for his organization.
Which of the following threat intelligence frameworks should he choose to perform such task?
HighCharts
SIGVERIF
Threat grid
TC complete
Answer: D
Question: 5
Karry, a threat analyst at an XYZ organization, is performing threat intelligence analysis. During the data collection phase, he used a data collection method that involves no participants and is purely based on analysis and observation of activities and processes going on within the local boundaries of the organization.
Identify the type data collection method used by the Karry.
Active data collection
Passive data collection
Exploited data collection
Raw data collection
Answer: B
Question: 6
During the process of threat intelligence analysis, John, a threat analyst, successfully extracted an indication of adversaryâs information, such as Modus operandi, tools, communication channels, and forensics evasion strategies used by adversaries.
Identify the type of threat intelligence analysis is performed by John.
Operational threat intelligence analysis
Technical threat intelligence analysis
Strategic threat intelligence analysis
Tactical threat intelligence analysis
Answer: D
Question: 7
John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques.
What phase of the advanced persistent threat lifecycle is John currently in?
Initial intrusion
Search and exfiltration
Expansion
Persistence
Answer: C
Question: 8
An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery locations in the rapidly changing network of compromised bots. In this particular technique, a single domain name consists of multiple IP addresses.
Which of the following technique is used by the attacker?
DNS zone transfer
Dynamic DNS
DNS interrogation
Fast-Flux DNS
Answer: D
Question: 9
Mr. Bob, a threat analyst, is performing analysis of competing hypotheses (ACH). He has reached to a stage where he is required to apply his analysis skills effectively to reject as many hypotheses and select the best hypotheses from the identified bunch of hypotheses, and this is done with the help of listed evidence. Then, he prepares a matrix where all the screened hypotheses are placed on the top, and the listed evidence for the hypotheses are placed at the bottom.
What stage of ACH is Bob currently in?
Diagnostics
Evidence
Inconsistency
Refinement
Answer: A
Question: 10
Which of the following types of threat attribution deals with the identification of the specific person, society, or a country sponsoring a well-planned and executed intrusion or attack over its target?
Nation-state attribution
True attribution
Campaign attribution
Intrusion-set attribution
Answer: B
Question: 11
Joe works as a threat intelligence analyst with Xsecurity Inc. He is assessing the TI program by comparing the project results with the original objectives by reviewing project charter. He is also reviewing the list of expected deliverables to ensure that each of those is delivered to an acceptable level of quality.
Identify the activity that Joe is performing to assess a TI programâs success or failure.
Determining the fulfillment of stakeholders
Identifying areas of further improvement
Determining the costs and benefits associated with the program
Conducting a gap analysis
Answer: D
Question: 12
Jame, a professional hacker, is trying to hack the confidential information of a target organization. He identified the vulnerabilities in the target system and created a tailored deliverable malicious payload using an exploit and a backdoor to send it to the victim.
Which of the following phases of cyber kill chain methodology is Jame executing?
Reconnaissance
Installation
Weaponization
Exploitation
Answer: C
Question: 13
Michael, a threat analyst, works in an organization named TechTop, was asked to conduct a cyber-threat intelligence analysis. After obtaining information regarding threats, he has started analyzing the information and understanding the nature of the threats.
What stage of the cyber-threat intelligence is Michael currently in?
Unknown unknowns
Unknowns unknown
Known unknowns
Known knowns
Answer: C
Question: 14
Miley, an analyst, wants to reduce the amount of collected data and make the storing and sharing process easy. She uses filtering, tagging, and queuing technique to sort out the relevant and structured data from the large amounts of unstructured data.
Which of the following techniques was employed by Miley?
Sandboxing
Normalization
Data visualization
Convenience sampling
Answer: B
Question: 15
Steve works as an analyst in a UK-based firm. He was asked to perform network monitoring to find any evidence of
compromise. During the network monitoring, he came to know that there are multiple logins from different locations in a short time span. Moreover, he also observed certain irregular log in patterns from locations where the organization does not have business relations. This resembles that somebody is trying to steal confidential information.
Which of the following key indicators of compromise does this scenario present?
Unusual outbound network traffic
Unexpected patching of systems
Unusual activity through privileged user account
Geographical anomalies
Answer: D
User: Diana*****![]() ![]() ![]() ![]() ![]() Thanks to the accurate question bank provided by Killexams.com, I was able to pass the 312-85 exam on my first attempt with a 96% score. Although my score dropped to 78.75% due to bad marking, I still appreciate the great organization and efficient process employed by Killexams.com. I wish them continued success. |
User: Martin*****![]() ![]() ![]() ![]() ![]() It is challenging to find test material that has all the necessary capabilities required to take the 312-85 exam. But I consider myself lucky because I used the killexams.com material, which had all the required statistics and capabilities and was also very useful. The subjects covered in the provided practice tests were comprehensive, making the coaching and studying in each subject matter a seamless process. I urge my friends to undergo it. |
User: Rubal*****![]() ![]() ![]() ![]() ![]() For the 312-85 exam, I depended on the questions and answers provided by Killexams.com, and it delivered what I wished. I retained all that I needed to, and my marks of 92% were agreeable, contrasting with my 1-week struggle. Thanks to Killexams.com for their assistance, and their aid was not hard for me to understand as well. |
User: Mika*****![]() ![]() ![]() ![]() ![]() I owe my success in passing the 312-85 exam to Killexams.com exam prep materials. I had failed the exam on my first attempt, but their questions were so similar to the real ones that I passed with ease the second time around. Their format is easy to understand, and the information you learn sticks with you even after the exam. |
User: Dan*****![]() ![]() ![]() ![]() ![]() The EC-Council 312-85 Questions and Answers section saved me as I was not confident with the EC-Council 312-85 exam topics. Luckily, a friend suggested I try killexams.com EC-Council 312-85 practice tests. I registered and downloaded EC-Council 312-85 real questions, and it helped me pass the exam quickly. I wish I had purchased it earlier, as it could have saved me a lot of time and money. |
Features of iPass4sure 312-85 Exam
- Files: PDF / Test Engine
- Premium Access
- Online Test Engine
- Instant download Access
- Comprehensive Q&A
- Success Rate
- Real Questions
- Updated Regularly
- Portable Files
- Unlimited Download
- 100% Secured
- Confidentiality: 100%
- Success Guarantee: 100%
- Any Hidden Cost: $0.00
- Auto Recharge: No
- Updates Intimation: by Email
- Technical Support: Free
- PDF Compatibility: Windows, Android, iOS, Linux
- Test Engine Compatibility: Mac / Windows / Android / iOS / Linux
Premium PDF with 281 Q&A
Get Full VersionAll EC-Council Exams
EC-Council ExamsCertification and Entry Test Exams
Complete exam list