100% Updated ECCouncil 312-85 Enterprise PDF Dumps [Q12-Q34]

Share

100% Updated ECCouncil 312-85 Enterprise PDF Dumps

Use Valid Exam 312-85 by ExamsLabs Books For Free Website

NEW QUESTION 12
Michael, a threat analyst, works in an organization named TechTop, was asked to conduct a cyber-threat intelligence analysis. After obtaining information regarding threats, he has started analyzing the information and understanding the nature of the threats.
What stage of the cyber-threat intelligence is Michael currently in?

  • A. Unknown unknowns
  • B. Known unknowns
  • C. Unknowns unknown
  • D. Known knowns

Answer: B

 

NEW QUESTION 13
Alice, a threat intelligence analyst at HiTech Cyber Solutions, wants to gather information for identifying emerging threats to the organization and implement essential techniques to prevent their systems and networks from such attacks. Alice is searching for online sources to obtain information such as the method used to launch an attack, and techniques and tools used to perform an attack and the procedures followed for covering the tracks after an attack.
Which of the following online sources should Alice use to gather such information?

  • A. Job sites
  • B. Social network settings
  • C. Hacking forums
  • D. Financial services

Answer: C

 

NEW QUESTION 14
Bob, a threat analyst, works in an organization named TechTop. He was asked to collect intelligence to fulfil the needs and requirements of the Red Tam present within the organization.
Which of the following are the needs of a RedTeam?

  • A. Intelligence extracted latest attacks analysis on similar organizations, which includes details about latest threats and TTPs
  • B. Intelligence on latest vulnerabilities, threat actors, and their tactics, techniques, and procedures (TTPs)
  • C. Intelligence related to increased attacks targeting a particular software or operating system vulnerability
  • D. Intelligence that reveals risks related to various strategic business decisions

Answer: B

 

NEW QUESTION 15
Which of the following types of threat attribution deals with the identification of the specific person, society, or a country sponsoring a well-planned and executed intrusion or attack over its target?

  • A. Nation-state attribution
  • B. True attribution
  • C. Campaign attribution
  • D. Intrusion-set attribution

Answer: B

 

NEW QUESTION 16
A network administrator working in an ABC organization collected log files generated by a traffic monitoring system, which may not seem to have useful information, but after performing proper analysis by him, the same information can be used to detect an attack in the network.
Which of the following categories of threat information has he collected?

  • A. Strategic reports
  • B. Detection indicators
  • C. Low-level data
  • D. Advisories

Answer: B

 

NEW QUESTION 17
Henry. a threat intelligence analyst at ABC Inc., is working on a threat intelligence program. He was assigned to work on establishing criteria for prioritization of intelligence needs and requirements.
Which of the following considerations must be employed by Henry to prioritize intelligence requirements?

  • A. Develop a collection plan
  • B. Produce actionable data
  • C. Understand data reliability
  • D. Understand frequency and impact of a threat

Answer: D

 

NEW QUESTION 18
Tyrion, a professional hacker, is targeting an organization to steal confidential information. He wants to perform website footprinting to obtain the following information, which is hidden in the web page header.
Connection status and content type
Accept-ranges and last-modified information
X-powered-by information
Web server in use and its version
Which of the following tools should the Tyrion use to view header content?

  • A. AutoShun
  • B. Vanguard enforcer
  • C. Hydra
  • D. Burp suite

Answer: D

 

NEW QUESTION 19
Moses, a threat intelligence analyst at InfoTec Inc., wants to find crucial information about the potential threats the organization is facing by using advanced Google search operators. He wants to identify whether any fake websites are hosted at the similar to the organization's URL.
Which of the following Google search queries should Moses use?

  • A. link: www.infothech.org
  • B. related: www.infothech.org
  • C. info: www.infothech.org
  • D. cache: www.infothech.org

Answer: B

 

NEW QUESTION 20
An analyst is conducting threat intelligence analysis in a client organization, and during the information gathering process, he gathered information from the publicly available sources and analyzed to obtain a rich useful form of intelligence. The information source that he used is primarily used for national security, law enforcement, and for collecting intelligence required for business or strategic decision making.
Which of the following sources of intelligence did the analyst use to collect information?

  • A. OSINT
  • B. ISAC
  • C. OPSEC
  • D. SIGINT

Answer: A

 

NEW QUESTION 21
Sarah is a security operations center (SOC) analyst working at JW Williams and Sons organization based in Chicago. As a part of security operations, she contacts information providers (sharing partners) for gathering information such as collections of validated and prioritized threat indicators along with a detailed technical analysis of malware samples, botnets, DDoS attack methods, and various other malicious tools. She further used the collected information at the tactical and operational levels.
Sarah obtained the required information from which of the following types of sharing partner?

  • A. Providers of threat data feeds
  • B. Providers of comprehensive cyber-threat intelligence
  • C. Providers of threat indicators
  • D. Providers of threat actors

Answer: B

 

NEW QUESTION 22
Sam works as an analyst in an organization named InfoTech Security. He was asked to collect information from various threat intelligence sources. In meeting the deadline, he forgot to verify the threat intelligence sources and used data from an open-source data provider, who offered it at a very low cost. Through it was beneficial at the initial stage but relying on such data providers can produce unreliable data and noise putting the organization network into risk.
What mistake Sam did that led to this situation?

  • A. Sam did not use the proper technology to use or consume the information.
  • B. Sam used unreliable intelligence sources.
  • C. Sam did not use the proper standardization formats for representing threat data.
  • D. Sam used data without context.

Answer: A

 

NEW QUESTION 23
In a team of threat analysts, two individuals were competing over projecting their own hypotheses on a given malware. However, to find logical proofs to confirm their hypotheses, the threat intelligence manager used a de-biasing strategy that involves learning strategic decision making in the circumstances comprising multistep interactions with numerous representatives, either having or without any perfect relevant information.
Which of the following de-biasing strategies the threat intelligence manager used to confirm their hypotheses?

  • A. Game theory
  • B. Cognitive psychology
  • C. Decision theory
  • D. Machine learning

Answer: C

 

NEW QUESTION 24
A team of threat intelligence analysts is performing threat analysis on malware, and each of them has come up with their own theory and evidence to support their theory on a given malware.
Now, to identify the most consistent theory out of all the theories, which of the following analytic processes must threat intelligence manager use?

  • A. Analysis of competing hypotheses (ACH)
  • B. Application decomposition and analysis (ADA)
  • C. Threat modelling
  • D. Automated technical analysis

Answer: A

 

NEW QUESTION 25
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?

  • A. Active online attack
  • B. Advanced persistent attack
  • C. Distributed network attack
  • D. Zero-day attack

Answer: D

 

NEW QUESTION 26
Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information from a variety of sources. He wants to use this information to develop security policies to enhance the overall security posture of his organization.
Which of the following sharing platforms should be used by Kim?

  • A. Blueliv threat exchange network
  • B. Cuckoo sandbox
  • C. OmniPeek
  • D. PortDroid network analysis

Answer: A

 

NEW QUESTION 27
During the process of threat intelligence analysis, John, a threat analyst, successfully extracted an indication of adversary's information, such as Modus operandi, tools, communication channels, and forensics evasion strategies used by adversaries.
Identify the type of threat intelligence analysis is performed by John.

  • A. Technical threat intelligence analysis
  • B. Strategic threat intelligence analysis
  • C. Tactical threat intelligence analysis
  • D. Operational threat intelligence analysis

Answer: C

 

NEW QUESTION 28
Joe works as a threat intelligence analyst with Xsecurity Inc. He is assessing the TI program by comparing the project results with the original objectives by reviewing project charter. He is also reviewing the list of expected deliverables to ensure that each of those is delivered to an acceptable level of quality.
Identify the activity that Joe is performing to assess a TI program's success or failure.

  • A. Determining the costs and benefits associated with the program
  • B. Identifying areas of further improvement
  • C. Determining the fulfillment of stakeholders
  • D. Conducting a gap analysis

Answer: D

 

NEW QUESTION 29
Daniel is a professional hacker whose aim is to attack a system to steal data and money for profit. He performs hacking to obtain confidential data such as social security numbers, personally identifiable information (PII) of an employee, and credit card information. After obtaining confidential data, he further sells the information on the black market to make money.
Daniel comes under which of the following types of threat actor.

  • A. Insider threat
  • B. State-sponsored hackers
  • C. Organized hackers
  • D. Industrial spies

Answer: C

 

NEW QUESTION 30
Lizzy, an analyst, wants to recognize the level of risks to the organization so as to plan countermeasures against cyber attacks. She used a threat modelling methodology where she performed the following stages:
Stage 1: Build asset-based threat profiles
Stage 2: Identify infrastructure vulnerabilities
Stage 3: Develop security strategy and plans
Which of the following threat modelling methodologies was used by Lizzy in the aforementioned scenario?

  • A. OCTAVE
  • B. DREAD
  • C. TRIKE
  • D. VAST

Answer: A

 

NEW QUESTION 31
Miley, an analyst, wants to reduce the amount of collected data and make the storing and sharing process easy. She uses filtering, tagging, and queuing technique to sort out the relevant and structured data from the large amounts of unstructured data.
Which of the following techniques was employed by Miley?

  • A. Data visualization
  • B. Sandboxing
  • C. Convenience sampling
  • D. Normalization

Answer: D

 

NEW QUESTION 32
......

ECCouncil 312-85 Official Cert Guide PDF: https://www.examslabs.com/ECCouncil/Certified-Threat-Intelligence-Analyst/best-312-85-exam-dumps.html

Free Certified Threat Intelligence Analyst 312-85 Official Cert Guide PDF Download: https://drive.google.com/open?id=1hmHsV-ZADZ9IJNUuoIBWr30XTfKW6z4A