
[2022年01月]更新のECCouncil 312-85試験練習テスト問題
更新された認定試験312-85問題集で練習テスト問題
質問 11
Sarah is a security operations center (SOC) analyst working at JW Williams and Sons organization based in Chicago. As a part of security operations, she contacts information providers (sharing partners) for gathering information such as collections of validated and prioritized threat indicators along with a detailed technical analysis of malware samples, botnets, DDoS attack methods, and various other malicious tools. She further used the collected information at the tactical and operational levels.
Sarah obtained the required information from which of the following types of sharing partner?
- A. Providers of threat actors
- B. Providers of threat indicators
- C. Providers of threat data feeds
- D. Providers of comprehensive cyber-threat intelligence
正解: D
質問 12
Alice, an analyst, shared information with security operation managers and network operations center (NOC) staff for protecting the organizational resources against various threats. Information shared by Alice was highly technical and include threat actor TTPs, malware campaigns, tools used by threat actors, and so on.
Which of the following types of threat intelligence was shared by Alice?
- A. Strategic threat intelligence
- B. Technical threat intelligence
- C. Operational threat intelligence
- D. Tactical threat intelligence
正解: B
質問 13
In which of the following forms of bulk data collection are large amounts of data first collected from multiple sources in multiple formats and then processed to achieve threat intelligence?
- A. Hybrid form
- B. Unstructured form
- C. Production form
- D. Structured form
正解: B
質問 14
Jian is a member of the security team at Trinity, Inc. He was conducting a real-time assessment of system activities in order to acquire threat intelligence feeds. He acquired feeds from sources like honeynets, P2P monitoring. infrastructure, and application logs.
Which of the following categories of threat intelligence feed was acquired by Jian?
- A. Internal intelligence feeds
- B. CSV data feeds
- C. Proactive surveillance feeds
- D. External intelligence feeds
正解: A
質問 15
John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques.
What phase of the advanced persistent threat lifecycle is John currently in?
- A. Persistence
- B. Search and exfiltration
- C. Expansion
- D. Initial intrusion
正解: C
質問 16
Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information from a variety of sources. He wants to use this information to develop security policies to enhance the overall security posture of his organization.
Which of the following sharing platforms should be used by Kim?
- A. OmniPeek
- B. Blueliv threat exchange network
- C. Cuckoo sandbox
- D. PortDroid network analysis
正解: B
質問 17
Andrews and Sons Corp. has decided to share threat information among sharing partners. Garry, a threat analyst, working in Andrews and Sons Corp., has asked to follow a trust model necessary to establish trust between sharing partners. In the trust model used by him, the first organization makes use of a body of evidence in a second organization, and the level of trust between two organizations depends on the degree and quality of evidence provided by the first organization.
Which of the following types of trust model is used by Garry to establish the trust?
- A. Mandated trust
- B. Mediated trust
- C. Direct historical trust
- D. Validated trust
正解: D
質問 18
Henry. a threat intelligence analyst at ABC Inc., is working on a threat intelligence program. He was assigned to work on establishing criteria for prioritization of intelligence needs and requirements.
Which of the following considerations must be employed by Henry to prioritize intelligence requirements?
- A. Develop a collection plan
- B. Produce actionable data
- C. Understand data reliability
- D. Understand frequency and impact of a threat
正解: D
質問 19
Which of the following components refers to a node in the network that routes the traffic from a workstation to external command and control server and helps in identification of installed malware in the network?
- A. Repeater
- B. Network interface card (NIC)
- C. Gateway
- D. Hub
正解: C
質問 20
Enrage Tech Company hired Enrique, a security analyst, for performing threat intelligence analysis. While performing data collection process, he used a counterintelligence mechanism where a recursive DNS server is employed to perform interserver DNS communication and when a request is generated from any name server to the recursive DNS server, the recursive DNS servers log the responses that are received. Then it replicates the logged data and stores the data in the central database. Using these logs, he analyzed the malicious attempts that took place over DNS infrastructure.
Which of the following cyber counterintelligence (CCI) gathering technique has Enrique used for data collection?
- A. Data collection through DNS zone transfer
- B. Data collection through dynamic DNS (DDNS)
- C. Data collection through passive DNS monitoring
- D. Data collection through DNS interrogation
正解: D
質問 21
Steve works as an analyst in a UK-based firm. He was asked to perform network monitoring to find any evidence of compromise. During the network monitoring, he came to know that there are multiple logins from different locations in a short time span. Moreover, he also observed certain irregular log in patterns from locations where the organization does not have business relations. This resembles that somebody is trying to steal confidential information.
Which of the following key indicators of compromise does this scenario present?
- A. Geographical anomalies
- B. Unexpected patching of systems
- C. Unusual activity through privileged user account
- D. Unusual outbound network traffic
正解: C
質問 22
Moses, a threat intelligence analyst at InfoTec Inc., wants to find crucial information about the potential threats the organization is facing by using advanced Google search operators. He wants to identify whether any fake websites are hosted at the similar to the organization's URL.
Which of the following Google search queries should Moses use?
- A. link: www.infothech.org
- B. related: www.infothech.org
- C. cache: www.infothech.org
- D. info: www.infothech.org
正解: B
質問 23
An analyst is conducting threat intelligence analysis in a client organization, and during the information gathering process, he gathered information from the publicly available sources and analyzed to obtain a rich useful form of intelligence. The information source that he used is primarily used for national security, law enforcement, and for collecting intelligence required for business or strategic decision making.
Which of the following sources of intelligence did the analyst use to collect information?
- A. SIGINT
- B. OSINT
- C. OPSEC
- D. ISAC
正解: B
質問 24
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?
- A. Distributed network attack
- B. Advanced persistent attack
- C. Zero-day attack
- D. Active online attack
正解: C
質問 25
H&P, Inc. is a small-scale organization that has decided to outsource the network security monitoring due to lack of resources in the organization. They are looking for the options where they can directly incorporate threat intelligence into their existing network defense solutions.
Which of the following is the most cost-effective methods the organization can employ?
- A. Look for an individual within the organization
- B. Recruit data management solution provider
- C. Recruit managed security service providers (MSSP)
- D. Recruit the right talent
正解: C
質問 26
......
ECCouncil 312-85 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
| トピック 7 |
|
| トピック 8 |
|
| トピック 9 |
|
| トピック 10 |
|
| トピック 11 |
|
| トピック 12 |
|
更新された検証済みの312-85問題集と解答で合格保証もしくは全額返金:https://www.jpntest.com/shiken/312-85-mondaishu
312-85のPDF問題とテストエンジンには50問があります:https://drive.google.com/open?id=1LStacSEzEnVgQrw_DTgRkY84tEvbG79l