
2023 The Most Effective 312-85 with 50 Questions Answers
Try Free and Start Using Realistic Verified 312-85 Dumps Instantly.
ECCouncil 312-85 (Certified Threat Intelligence Analyst) certification exam is an essential credential for professionals looking to acquire advanced threat intelligence skills. 312-85 exam covers a wide range of topics and requires a significant amount of preparation to be successful. Certified Threat Intelligence Analyst certification is highly respected in the industry and is recognized as a benchmark for measuring the expertise of professionals in threat intelligence analysis.
The CTIA certification is ideal for cybersecurity professionals who are responsible for identifying and mitigating threats within their organizations. It is especially relevant for security analysts, threat intelligence analysts, security engineers, security consultants, and security managers. The CTIA certification can help professionals enhance their skills and knowledge in the field of threat intelligence and improve their career prospects.
NEW QUESTION # 26
Alison, an analyst in an XYZ organization, wants to retrieve information about a company's website from the time of its inception as well as the removed information from the target website.
What should Alison do to get the information he needs.
- A. Alison should run the Web Data Extractor tool to extract the required website information.
- B. Alison should use https://archive.org to extract the required website information.
- C. Alison should recover cached pages of the website from the Google search engine cache to extract the required website information.
- D. Alison should use SmartWhois to extract the required website information.
Answer: B
NEW QUESTION # 27
Alice, a threat intelligence analyst at HiTech Cyber Solutions, wants to gather information for identifying emerging threats to the organization and implement essential techniques to prevent their systems and networks from such attacks. Alice is searching for online sources to obtain information such as the method used to launch an attack, and techniques and tools used to perform an attack and the procedures followed for covering the tracks after an attack.
Which of the following online sources should Alice use to gather such information?
- A. Financial services
- B. Social network settings
- C. Job sites
- D. Hacking forums
Answer: D
NEW QUESTION # 28
Which of the following components refers to a node in the network that routes the traffic from a workstation to external command and control server and helps in identification of installed malware in the network?
- A. Hub
- B. Network interface card (NIC)
- C. Repeater
- D. Gateway
Answer: D
NEW QUESTION # 29
An analyst wants to disseminate the information effectively so that the consumers can acquire and benefit out of the intelligence.
Which of the following criteria must an analyst consider in order to make the intelligence concise, to the point, accurate, and easily understandable and must consist of a right balance between tables, narrative, numbers, graphics, and multimedia?
- A. The right content
- B. The right time
- C. The right order
- D. The right presentation
Answer: D
NEW QUESTION # 30
H&P, Inc. is a small-scale organization that has decided to outsource the network security monitoring due to lack of resources in the organization. They are looking for the options where they can directly incorporate threat intelligence into their existing network defense solutions.
Which of the following is the most cost-effective methods the organization can employ?
- A. Recruit the right talent
- B. Recruit managed security service providers (MSSP)
- C. Recruit data management solution provider
- D. Look for an individual within the organization
Answer: B
NEW QUESTION # 31
Cybersol Technologies initiated a cyber-threat intelligence program with a team of threat intelligence analysts. During the process, the analysts started converting the raw data into useful information by applying various techniques, such as machine-based techniques, and statistical methods.
In which of the following phases of the threat intelligence lifecycle is the threat intelligence team currently working?
- A. Dissemination and integration
- B. Analysis and production
- C. Planning and direction
- D. Processing and exploitation
Answer: D
NEW QUESTION # 32
SecurityTech Inc. is developing a TI plan where it can drive more advantages in less funds. In the process of selecting a TI platform, it wants to incorporate a feature that ranks elements such as intelligence sources, threat actors, attacks, and digital assets of the organization, so that it can put in more funds toward the resources which are critical for the organization's security.
Which of the following key features should SecurityTech Inc. consider in their TI plan for selecting the TI platform?
- A. Workflow
- B. Open
- C. Search
- D. Scoring
Answer: D
NEW QUESTION # 33
In which of the following storage architecture is the data stored in a localized system, server, or storage hardware and capable of storing a limited amount of data in its database and locally available for data usage?
- A. Centralized storage
- B. Distributed storage
- C. Cloud storage
- D. Object-based storage
Answer: D
NEW QUESTION # 34
Steve works as an analyst in a UK-based firm. He was asked to perform network monitoring to find any evidence of compromise. During the network monitoring, he came to know that there are multiple logins from different locations in a short time span. Moreover, he also observed certain irregular log in patterns from locations where the organization does not have business relations. This resembles that somebody is trying to steal confidential information.
Which of the following key indicators of compromise does this scenario present?
- A. Geographical anomalies
- B. Unusual activity through privileged user account
- C. Unusual outbound network traffic
- D. Unexpected patching of systems
Answer: B
NEW QUESTION # 35
In which of the following storage architecture is the data stored in a localized system, server, or storage hardware and capable of storing a limited amount of data in its database and locally available for data usage?
- A. Centralized storage
- B. Distributed storage
- C. Cloud storage
- D. Object-based storage
Answer: A
NEW QUESTION # 36
Andrews and Sons Corp. has decided to share threat information among sharing partners. Garry, a threat analyst, working in Andrews and Sons Corp., has asked to follow a trust model necessary to establish trust between sharing partners. In the trust model used by him, the first organization makes use of a body of evidence in a second organization, and the level of trust between two organizations depends on the degree and quality of evidence provided by the first organization.
Which of the following types of trust model is used by Garry to establish the trust?
- A. Mediated trust
- B. Direct historical trust
- C. Mandated trust
- D. Validated trust
Answer: D
NEW QUESTION # 37
In which of the following forms of bulk data collection are large amounts of data first collected from multiple sources in multiple formats and then processed to achieve threat intelligence?
- A. Production form
- B. Structured form
- C. Hybrid form
- D. Unstructured form
Answer: D
NEW QUESTION # 38
Jame, a professional hacker, is trying to hack the confidential information of a target organization. He identified the vulnerabilities in the target system and created a tailored deliverable malicious payload using an exploit and a backdoor to send it to the victim.
Which of the following phases of cyber kill chain methodology is Jame executing?
- A. Installation
- B. Weaponization
- C. Exploitation
- D. Reconnaissance
Answer: B
NEW QUESTION # 39
Moses, a threat intelligence analyst at InfoTec Inc., wants to find crucial information about the potential threats the organization is facing by using advanced Google search operators. He wants to identify whether any fake websites are hosted at the similar to the organization's URL.
Which of the following Google search queries should Moses use?
- A. cache: www.infothech.org
- B. related: www.infothech.org
- C. info: www.infothech.org
- D. link: www.infothech.org
Answer: B
NEW QUESTION # 40
Alison, an analyst in an XYZ organization, wants to retrieve information about a company's website from the time of its inception as well as the removed information from the target website.
What should Alison do to get the information he needs.
- A. Alison should recover cached pages of the website from the Google search engine cache to extract the required website information.
- B. Alison should run the Web Data Extractor tool to extract the required website information.
- C. Alison should use SmartWhois to extract the required website information.
- D. Alison should use https://archive.org to extract the required website information.
Answer: B
NEW QUESTION # 41
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?
- A. Distributed network attack
- B. Active online attack
- C. Zero-day attack
- D. Advanced persistent attack
Answer: C
NEW QUESTION # 42
Alice, an analyst, shared information with security operation managers and network operations center (NOC) staff for protecting the organizational resources against various threats. Information shared by Alice was highly technical and include threat actor TTPs, malware campaigns, tools used by threat actors, and so on.
Which of the following types of threat intelligence was shared by Alice?
- A. Strategic threat intelligence
- B. Tactical threat intelligence
- C. Technical threat intelligence
- D. Operational threat intelligence
Answer: C
NEW QUESTION # 43
A team of threat intelligence analysts is performing threat analysis on malware, and each of them has come up with their own theory and evidence to support their theory on a given malware.
Now, to identify the most consistent theory out of all the theories, which of the following analytic processes must threat intelligence manager use?
- A. Application decomposition and analysis (ADA)
- B. Threat modelling
- C. Automated technical analysis
- D. Analysis of competing hypotheses (ACH)
Answer: D
NEW QUESTION # 44
During the process of threat intelligence analysis, John, a threat analyst, successfully extracted an indication of adversary's information, such as Modus operandi, tools, communication channels, and forensics evasion strategies used by adversaries.
Identify the type of threat intelligence analysis is performed by John.
- A. Tactical threat intelligence analysis
- B. Technical threat intelligence analysis
- C. Strategic threat intelligence analysis
- D. Operational threat intelligence analysis
Answer: A
NEW QUESTION # 45
Walter and Sons Company has faced major cyber attacks and lost confidential dat a. The company has decided to concentrate more on the security rather than other resources. Therefore, they hired Alice, a threat analyst, to perform data analysis. Alice was asked to perform qualitative data analysis to extract useful information from collected bulk data.
Which of the following techniques will help Alice to perform qualitative data analysis?
- A. Regression analysis, variance analysis, and so on
- B. Brainstorming, interviewing, SWOT analysis, Delphi technique, and so on
- C. Finding links between data and discover threat-related information
- D. Numerical calculations, statistical modeling, measurement, research, and so on.
Answer: B
NEW QUESTION # 46
Jim works as a security analyst in a large multinational company. Recently, a group of hackers penetrated into their organizational network and used a data staging technique to collect sensitive dat a. They collected all sorts of sensitive data about the employees and customers, business tactics of the organization, financial information, network infrastructure information and so on.
What should Jim do to detect the data staging before the hackers exfiltrate from the network?
- A. Jim should identify the attack at an initial stage by checking the content of the user agent field.
- B. Jim should monitor network traffic for malicious file transfers, file integrity monitoring, and event logs.
- C. Jim should analyze malicious DNS requests, DNS payload, unspecified domains, and destination of DNS requests.
- D. Jim should identify the web shell running in the network by analyzing server access, error logs, suspicious strings indicating encoding, user agent strings, and so on.
Answer: B
NEW QUESTION # 47
Which of the following types of threat attribution deals with the identification of the specific person, society, or a country sponsoring a well-planned and executed intrusion or attack over its target?
- A. True attribution
- B. Campaign attribution
- C. Nation-state attribution
- D. Intrusion-set attribution
Answer: A
NEW QUESTION # 48
Sam works as an analyst in an organization named InfoTech Security. He was asked to collect information from various threat intelligence sources. In meeting the deadline, he forgot to verify the threat intelligence sources and used data from an open-source data provider, who offered it at a very low cost. Through it was beneficial at the initial stage but relying on such data providers can produce unreliable data and noise putting the organization network into risk.
What mistake Sam did that led to this situation?
- A. Sam used data without context.
- B. Sam used unreliable intelligence sources.
- C. Sam did not use the proper standardization formats for representing threat data.
- D. Sam did not use the proper technology to use or consume the information.
Answer: D
NEW QUESTION # 49
......
Download Free Latest Exam 312-85 Certified Sample Questions: https://www.validtorrent.com/312-85-valid-exam-torrent.html
312-85 Actual Questions - Instant Download 50 Questions: https://drive.google.com/open?id=1qXmZDvF_3-gymYf2pY5TnBJtR20BwH4L