DumpsFree provides high-quality dumps PDF & dumps VCE for candidates who are willing to pass exams and get certifications soon. We provide dumps free download before purchasing dumps VCE. 100% pass exam!

Get 312-85 Braindumps & 312-85 Real Exam Questions [Q30-Q47]

Share

Get 312-85 Braindumps & 312-85 Real Exam Questions

ECCouncil 312-85 Actual Questions and Braindumps


ECCouncil 312-85 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Understanding Indicators of Compromise
  • Understanding Advanced Persistent Threats
Topic 2
  • Overview of Threat Intelligence Sharing
  • Requirements, Planning, Direction, and Review
Topic 3
  • Overview of Threat Intelligence Integration
  • Overview of Threat Intelligence Reports
Topic 4
  • Overview of Intelligence Sharing Acts and Regulations
  • Understanding the Threat Analysis Process
Topic 5
  • Understanding Threat Intelligence Sharing Platforms
  • Understanding Data Processing and Exploitation
Topic 6
  • Understanding Cyber Threat Intelligence
  • Understanding Intelligence
Topic 7
  • Overview of Threat Intelligence Feeds and Sources
  • Overview of Threat Intelligence Data Collection
Topic 8
  • Understanding Organization’s Current Threat Landscape
  • Reviewing Threat Intelligence Program
Topic 9
  • Cyber Threats and Kill Chain Methodology
  • Understanding Cyber Kill Chain
Topic 10
  • Overview of Threat Intelligence Lifecycle and Frameworks
  • Introduction to Threat Intelligence
Topic 11
  • Understanding Requirements Analysis
  • Building a Threat Intelligence Team
Topic 12
  • Understanding Threat Intelligence Data Collection and Acquisition
  • Overview of Threat Intelligence Collection Management
Topic 13
  • Overview of Fine-Tuning Threat Analysis
  • Understanding Threat Intelligence Evaluation

 

NEW QUESTION 30
Mr. Bob, a threat analyst, is performing analysis of competing hypotheses (ACH). He has reached to a stage where he is required to apply his analysis skills effectively to reject as many hypotheses and select the best hypotheses from the identified bunch of hypotheses, and this is done with the help of listed evidence. Then, he prepares a matrix where all the screened hypotheses are placed on the top, and the listed evidence for the hypotheses are placed at the bottom.
What stage of ACH is Bob currently in?

  • A. Inconsistency
  • B. Diagnostics
  • C. Refinement
  • D. Evidence

Answer: B

 

NEW QUESTION 31
A team of threat intelligence analysts is performing threat analysis on malware, and each of them has come up with their own theory and evidence to support their theory on a given malware.
Now, to identify the most consistent theory out of all the theories, which of the following analytic processes must threat intelligence manager use?

  • A. Automated technical analysis
  • B. Threat modelling
  • C. Application decomposition and analysis (ADA)
  • D. Analysis of competing hypotheses (ACH)

Answer: D

 

NEW QUESTION 32
Which of the following components refers to a node in the network that routes the traffic from a workstation to external command and control server and helps in identification of installed malware in the network?

  • A. Network interface card (NIC)
  • B. Repeater
  • C. Hub
  • D. Gateway

Answer: D

 

NEW QUESTION 33
Alice, a threat intelligence analyst at HiTech Cyber Solutions, wants to gather information for identifying emerging threats to the organization and implement essential techniques to prevent their systems and networks from such attacks. Alice is searching for online sources to obtain information such as the method used to launch an attack, and techniques and tools used to perform an attack and the procedures followed for covering the tracks after an attack.
Which of the following online sources should Alice use to gather such information?

  • A. Job sites
  • B. Financial services
  • C. Social network settings
  • D. Hacking forums

Answer: D

 

NEW QUESTION 34
During the process of threat intelligence analysis, John, a threat analyst, successfully extracted an indication of adversary's information, such as Modus operandi, tools, communication channels, and forensics evasion strategies used by adversaries.
Identify the type of threat intelligence analysis is performed by John.

  • A. Technical threat intelligence analysis
  • B. Operational threat intelligence analysis
  • C. Tactical threat intelligence analysis
  • D. Strategic threat intelligence analysis

Answer: C

 

NEW QUESTION 35
Miley, an analyst, wants to reduce the amount of collected data and make the storing and sharing process easy. She uses filtering, tagging, and queuing technique to sort out the relevant and structured data from the large amounts of unstructured data.
Which of the following techniques was employed by Miley?

  • A. Data visualization
  • B. Sandboxing
  • C. Convenience sampling
  • D. Normalization

Answer: D

 

NEW QUESTION 36
Michael, a threat analyst, works in an organization named TechTop, was asked to conduct a cyber-threat intelligence analysis. After obtaining information regarding threats, he has started analyzing the information and understanding the nature of the threats.
What stage of the cyber-threat intelligence is Michael currently in?

  • A. Known knowns
  • B. Unknowns unknown
  • C. Unknown unknowns
  • D. Known unknowns

Answer: D

 

NEW QUESTION 37
Alison, an analyst in an XYZ organization, wants to retrieve information about a company's website from the time of its inception as well as the removed information from the target website.
What should Alison do to get the information he needs.

  • A. Alison should recover cached pages of the website from the Google search engine cache to extract the required website information.
  • B. Alison should run the Web Data Extractor tool to extract the required website information.
  • C. Alison should use SmartWhois to extract the required website information.
  • D. Alison should use https://archive.org to extract the required website information.

Answer: B

 

NEW QUESTION 38
An analyst is conducting threat intelligence analysis in a client organization, and during the information gathering process, he gathered information from the publicly available sources and analyzed to obtain a rich useful form of intelligence. The information source that he used is primarily used for national security, law enforcement, and for collecting intelligence required for business or strategic decision making.
Which of the following sources of intelligence did the analyst use to collect information?

  • A. ISAC
  • B. OPSEC
  • C. OSINT
  • D. SIGINT

Answer: C

 

NEW QUESTION 39
Which of the following types of threat attribution deals with the identification of the specific person, society, or a country sponsoring a well-planned and executed intrusion or attack over its target?

  • A. Intrusion-set attribution
  • B. Campaign attribution
  • C. Nation-state attribution
  • D. True attribution

Answer: D

 

NEW QUESTION 40
Kathy wants to ensure that she shares threat intelligence containing sensitive information with the appropriate audience. Hence, she used traffic light protocol (TLP).
Which TLP color would you signify that information should be shared only within a particular community?

  • A. White
  • B. Red
  • C. Green
  • D. Amber

Answer: D

 

NEW QUESTION 41
In which of the following storage architecture is the data stored in a localized system, server, or storage hardware and capable of storing a limited amount of data in its database and locally available for data usage?

  • A. Distributed storage
  • B. Centralized storage
  • C. Object-based storage
  • D. Cloud storage

Answer: C

 

NEW QUESTION 42
An analyst wants to disseminate the information effectively so that the consumers can acquire and benefit out of the intelligence.
Which of the following criteria must an analyst consider in order to make the intelligence concise, to the point, accurate, and easily understandable and must consist of a right balance between tables, narrative, numbers, graphics, and multimedia?

  • A. The right content
  • B. The right presentation
  • C. The right order
  • D. The right time

Answer: B

 

NEW QUESTION 43
Sam works as an analyst in an organization named InfoTech Security. He was asked to collect information from various threat intelligence sources. In meeting the deadline, he forgot to verify the threat intelligence sources and used data from an open-source data provider, who offered it at a very low cost. Through it was beneficial at the initial stage but relying on such data providers can produce unreliable data and noise putting the organization network into risk.
What mistake Sam did that led to this situation?

  • A. Sam did not use the proper technology to use or consume the information.
  • B. Sam did not use the proper standardization formats for representing threat data.
  • C. Sam used data without context.
  • D. Sam used unreliable intelligence sources.

Answer: A

 

NEW QUESTION 44
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?

  • A. Zero-day attack
  • B. Advanced persistent attack
  • C. Active online attack
  • D. Distributed network attack

Answer: A

 

NEW QUESTION 45
Joe works as a threat intelligence analyst with Xsecurity Inc. He is assessing the TI program by comparing the project results with the original objectives by reviewing project charter. He is also reviewing the list of expected deliverables to ensure that each of those is delivered to an acceptable level of quality.
Identify the activity that Joe is performing to assess a TI program's success or failure.

  • A. Conducting a gap analysis
  • B. Identifying areas of further improvement
  • C. Determining the fulfillment of stakeholders
  • D. Determining the costs and benefits associated with the program

Answer: A

 

NEW QUESTION 46
In which of the following forms of bulk data collection are large amounts of data first collected from multiple sources in multiple formats and then processed to achieve threat intelligence?

  • A. Production form
  • B. Hybrid form
  • C. Unstructured form
  • D. Structured form

Answer: C

 

NEW QUESTION 47
......

312-85 Dumps To Pass ECCouncil Exam in 24 Hours - DumpsFree: https://www.dumpsfree.com/312-85-valid-exam.html

Buy Latest 312-85 Exam Q&A PDF - One Year Free Update: https://drive.google.com/open?id=1v6U4UwYCW0hQ9i4XUvZne42Na8s636s2