Eccouncil

312-85 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 57-question bank.

Provider
Eccouncil
Question bank
57
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for 312-85, a certification listed under Eccouncil. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Eccouncil. The certification credential is issued by Eccouncil, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Daniel is a professional hacker whose aim is to attack a system to steal data and money for profit. He performs hacking to obtain confidential data such as social security numbers, personally identifiable information (PII) of an employee, and credit card information. After obtaining confidential data, he further sells the information on the black market to make money. Daniel comes under which of the following types of threat actor.

    Choose one answer.

    • Industrial spies
    • State-sponsored hackers
    • Insider threat
    • Organized hackers
  2. Question 2 · 1

    John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques. What phase of the advanced persistent threat lifecycle is John currently in?

    Choose one answer.

    • Initial intrusion
    • Search and exfiltration
    • Expansion
    • Persistence
  3. Question 3 · 1

    Jim works as a security analyst in a large multinational company. Recently, a group of hackers penetrated into their organizational network and used a data staging technique to collect sensitive data. They collected all sorts of sensitive data about the employees and customers, business tactics of the organization, financial information, network infrastructure information and so on. What should Jim do to detect the data staging before the hackers exfiltrate from the network?

    Choose one answer.

    • Jim should identify the attack at an initial stage by checking the content of the user agent field.
    • Jim should analyze malicious DNS requests, DNS payload, unspecified domains, and destination of DNS requests.
    • Jim should monitor network traffic for malicious file transfers, file integrity monitoring, and event logs.
    • Jim should identify the web shell running in the network by analyzing server access, error logs, suspicious strings indicating encoding, user agent strings, and so on.
  4. Question 4 · 1

    Andrews and Sons Corp. has decided to share threat information among sharing partners. Garry, a threat analyst, working in Andrews and Sons Corp., has asked to follow a trust model necessary to establish trust between sharing partners. In the trust model used by him, the first organization makes use of a body of evidence in a second organization, and the level of trust between two organizations depends on the degree and quality of evidence provided by the first organization. Which of the following types of trust model is used by Garry to establish the trust?

    Choose one answer.

    • Mediated trust
    • Mandated trust
    • Direct historical trust
    • Validated trust
  5. Question 5 · 1

    A threat analyst obtains an intelligence related to a threat, where the data is sent in the form of a connection request from a remote host to the server. From this data, he obtains only the IP address of the source and destination but no contextual information. While processing this data, he obtains contextual information stating that multiple connection requests from different geo-locations are received by the server within a short time span, and as a result, the server is stressed and gradually its performance has reduced. He further performed analysis on the information based on the past and present experience and concludes the attack experienced by the client organization. Which of the following attacks is performed on the client organization?

    Choose one answer.

    • DHCP attacks
    • MAC spoofing attack
    • Distributed Denial-of-Service (DDoS) attack
    • Bandwidth attack
  6. Question 6 · 1

    Jame, a professional hacker, is trying to hack the confidential information of a target organization. He identified the vulnerabilities in the target system and created a tailored deliverable malicious payload using an exploit and a backdoor to send it to the victim. Which of the following phases of cyber kill chain methodology is Jame executing?

    Choose one answer.

    • Reconnaissance
    • Installation
    • Weaponization
    • Exploitation
  7. Question 7 · 1

    Steve works as an analyst in a UK-based firm. He was asked to perform network monitoring to find any evidence of compromise. During the network monitoring, he came to know that there are multiple logins from different locations in a short time span. Moreover, he also observed certain irregular log in patterns from locations where the organization does not have business relations. This resembles that somebody is trying to steal confidential information. Which of the following key indicators of compromise does this scenario present?

    Choose one answer.

    • Unusual outbound network traffic
    • Unexpected patching of systems
    • Unusual activity through privileged user account
    • Geographical anomalies
  8. Question 8 · 1

    Which of the following characteristics of APT refers to numerous attempts done by the attacker to gain entry to the target’s network?

    Choose one answer.

    • Risk tolerance
    • Timeliness
    • Attack origination points
    • Multiphased
  9. Question 9 · 1

    Lizzy, an analyst, wants to recognize the level of risks to the organization so as to plan countermeasures against cyber attacks. She used a threat modelling methodology where she performed the following stages: Stage 1: Build asset-based threat profiles Stage 2: Identify infrastructure vulnerabilities Stage 3: Develop security strategy and plans Which of the following threat modelling methodologies was used by Lizzy in the aforementioned scenario?

    Choose one answer.

    • TRIKE
    • VAST
    • OCTAVE
    • DREAD
  10. Question 10 · 1

    Which of the following types of threat attribution deals with the identification of the specific person, society, or a country sponsoring a well-planned and executed intrusion or attack over its target?

    Choose one answer.

    • Nation-state attribution
    • True attribution
    • Campaign attribution
    • Intrusion-set attribution
  11. Question 11 · 1

    In a team of threat analysts, two individuals were competing over projecting their own hypotheses on a given malware. However, to find logical proofs to confirm their hypotheses, the threat intelligence manager used a de-biasing strategy that involves learning strategic decision making in the circumstances comprising multistep interactions with numerous representatives, either having or without any perfect relevant information. Which of the following de-biasing strategies the threat intelligence manager used to confirm their hypotheses?

    Choose one answer.

    • Game theory
    • Machine learning
    • Decision theory
    • Cognitive psychology
  12. Question 12 · 1

    An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery locations in the rapidly changing network of compromised bots. In this particular technique, a single domain name consists of multiple IP addresses. Which of the following technique is used by the attacker?

    Choose one answer.

    • DNS zone transfer
    • Dynamic DNS
    • DNS interrogation
    • Fast-Flux DNS
  13. Question 13 · 1

    Cybersol Technologies initiated a cyber-threat intelligence program with a team of threat intelligence analysts. During the process, the analysts started converting the raw data into useful information by applying various techniques, such as machine-based techniques, and statistical methods. In which of the following phases of the threat intelligence lifecycle is the threat intelligence team currently working?

    Choose one answer.

    • Dissemination and integration
    • Planning and direction
    • Processing and exploitation
    • Analysis and production
  14. Question 14 · 1

    Jian is a member of the security team at Trinity, Inc. He was conducting a real-time assessment of system activities in order to acquire threat intelligence feeds. He acquired feeds from sources like honeynets, P2P monitoring. infrastructure, and application logs. Which of the following categories of threat intelligence feed was acquired by Jian?

    Choose one answer.

    • Internal intelligence feeds
    • External intelligence feeds
    • CSV data feeds
    • Proactive surveillance feeds
  15. Question 15 · 1

    Which of the following components refers to a node in the network that routes the traffic from a workstation to external command and control server and helps in identification of installed malware in the network?

    Choose one answer.

    • Repeater
    • Gateway
    • Hub
    • Network interface card (NIC)

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free