
Exam Questions and Answers for 312-85 Study Guide Questions and Answers!
Certified Threat Intelligence Analyst Certification Sample Questions and Practice Exam
The Certified Threat Intelligence Analyst (CTIA) certification exam offered by the ECCouncil is a highly sought-after certification in the field of cybersecurity. Certified Threat Intelligence Analyst certification is designed to equip cybersecurity professionals with the necessary skills and knowledge to identify and mitigate potential threats to an organization's digital assets. The CTIA certification exam tests the candidate's ability to analyze and interpret threat data, as well as their proficiency in using various intelligence tools to gather and analyze data.
NEW QUESTION # 15
What is the correct sequence of steps involved in scheduling a threat intelligence program?
1. Review the project charter
2. Identify all deliverables
3. Identify the sequence of activities
4. Identify task dependencies
5. Develop the final schedule
6. Estimate duration of each activity
7. Identify and estimate resources for all activities
8. Define all activities
9. Build a work breakdown structure (WBS)
- A. 1-->2-->3-->4-->5-->6-->7-->8-->9
- B. 3-->4-->5-->2-->1-->9-->8-->7-->6
- C. 1-->2-->3-->4-->5-->6-->9-->8-->7
- D. 1-->9-->2-->8-->3-->7-->4-->6-->5
Answer: D
NEW QUESTION # 16
Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information from a variety of sources. He wants to use this information to develop security policies to enhance the overall security posture of his organization.
Which of the following sharing platforms should be used by Kim?
- A. OmniPeek
- B. PortDroid network analysis
- C. Blueliv threat exchange network
- D. Cuckoo sandbox
Answer: C
NEW QUESTION # 17
Which of the following types of threat attribution deals with the identification of the specific person, society, or a country sponsoring a well-planned and executed intrusion or attack over its target?
- A. Intrusion-set attribution
- B. Nation-state attribution
- C. True attribution
- D. Campaign attribution
Answer: C
NEW QUESTION # 18
Tracy works as a CISO in a large multinational company. She consumes threat intelligence to understand the changing trends of cyber security. She requires intelligence to understand the current business trends and make appropriate decisions regarding new technologies, security budget, improvement of processes, and staff. The intelligence helps her in minimizing business risks and protecting the new technology and business initiatives.
Identify the type of threat intelligence consumer is Tracy.
- A. Strategic users
- B. Technical users
- C. Operational users
- D. Tactical users
Answer: A
NEW QUESTION # 19
Enrage Tech Company hired Enrique, a security analyst, for performing threat intelligence analysis. While performing data collection process, he used a counterintelligence mechanism where a recursive DNS server is employed to perform interserver DNS communication and when a request is generated from any name server to the recursive DNS server, the recursive DNS servers log the responses that are received. Then it replicates the logged data and stores the data in the central database. Using these logs, he analyzed the malicious attempts that took place over DNS infrastructure.
Which of the following cyber counterintelligence (CCI) gathering technique has Enrique used for data collection?
- A. Data collection through DNS zone transfer
- B. Data collection through passive DNS monitoring
- C. Data collection through DNS interrogation
- D. Data collection through dynamic DNS (DDNS)
Answer: C
NEW QUESTION # 20
Steve works as an analyst in a UK-based firm. He was asked to perform network monitoring to find any evidence of compromise. During the network monitoring, he came to know that there are multiple logins from different locations in a short time span. Moreover, he also observed certain irregular log in patterns from locations where the organization does not have business relations. This resembles that somebody is trying to steal confidential information.
Which of the following key indicators of compromise does this scenario present?
- A. Geographical anomalies
- B. Unusual activity through privileged user account
- C. Unexpected patching of systems
- D. Unusual outbound network traffic
Answer: B
NEW QUESTION # 21
Kathy wants to ensure that she shares threat intelligence containing sensitive information with the appropriate audience. Hence, she used traffic light protocol (TLP).
Which TLP color would you signify that information should be shared only within a particular community?
- A. Amber
- B. Green
- C. Red
- D. White
Answer: B
NEW QUESTION # 22
An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery locations in the rapidly changing network of compromised bots. In this particular technique, a single domain name consists of multiple IP addresses.
Which of the following technique is used by the attacker?
- A. Dynamic DNS
- B. DNS interrogation
- C. DNS zone transfer
- D. Fast-Flux DNS
Answer: D
NEW QUESTION # 23
John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques.
What phase of the advanced persistent threat lifecycle is John currently in?
- A. Persistence
- B. Search and exfiltration
- C. Initial intrusion
- D. Expansion
Answer: D
NEW QUESTION # 24
Mr. Bob, a threat analyst, is performing analysis of competing hypotheses (ACH). He has reached to a stage where he is required to apply his analysis skills effectively to reject as many hypotheses and select the best hypotheses from the identified bunch of hypotheses, and this is done with the help of listed evidence. Then, he prepares a matrix where all the screened hypotheses are placed on the top, and the listed evidence for the hypotheses are placed at the bottom.
What stage of ACH is Bob currently in?
- A. Inconsistency
- B. Refinement
- C. Evidence
- D. Diagnostics
Answer: D
NEW QUESTION # 25
Daniel is a professional hacker whose aim is to attack a system to steal data and money for profit. He performs hacking to obtain confidential data such as social security numbers, personally identifiable information (PII) of an employee, and credit card information. After obtaining confidential data, he further sells the information on the black market to make money.
Daniel comes under which of the following types of threat actor.
- A. State-sponsored hackers
- B. Industrial spies
- C. Insider threat
- D. Organized hackers
Answer: D
NEW QUESTION # 26
In a team of threat analysts, two individuals were competing over projecting their own hypotheses on a given malware. However, to find logical proofs to confirm their hypotheses, the threat intelligence manager used a de-biasing strategy that involves learning strategic decision making in the circumstances comprising multistep interactions with numerous representatives, either having or without any perfect relevant information.
Which of the following de-biasing strategies the threat intelligence manager used to confirm their hypotheses?
- A. Decision theory
- B. Game theory
- C. Cognitive psychology
- D. Machine learning
Answer: A
NEW QUESTION # 27
In which of the following forms of bulk data collection are large amounts of data first collected from multiple sources in multiple formats and then processed to achieve threat intelligence?
- A. Production form
- B. Hybrid form
- C. Unstructured form
- D. Structured form
Answer: C
NEW QUESTION # 28
A network administrator working in an ABC organization collected log files generated by a traffic monitoring system, which may not seem to have useful information, but after performing proper analysis by him, the same information can be used to detect an attack in the network.
Which of the following categories of threat information has he collected?
- A. Strategic reports
- B. Low-level data
- C. Detection indicators
- D. Advisories
Answer: C
NEW QUESTION # 29
In a team of threat analysts, two individuals were competing over projecting their own hypotheses on a given malware. However, to find logical proofs to confirm their hypotheses, the threat intelligence manager used a de-biasing strategy that involves learning strategic decision making in the circumstances comprising multistep interactions with numerous representatives, either having or without any perfect relevant information.
Which of the following de-biasing strategies the threat intelligence manager used to confirm their hypotheses?
- A. Decision theory
- B. Cognitive psychology
- C. Game theory
- D. Machine learning
Answer: C
NEW QUESTION # 30
......
312-85 certification dumps - Certified Threat Intelligence Analyst 312-85 guides - 100% valid: https://dumpstorrent.dumpsfree.com/312-85-valid-exam.html