[2022年01月]更新のECCouncil 312-85試験練習テスト問題 [Q11-Q26]

Share

[2022年01月]更新のECCouncil 312-85試験練習テスト問題

更新された認定試験312-85問題集で練習テスト問題

質問 11
Sarah is a security operations center (SOC) analyst working at JW Williams and Sons organization based in Chicago. As a part of security operations, she contacts information providers (sharing partners) for gathering information such as collections of validated and prioritized threat indicators along with a detailed technical analysis of malware samples, botnets, DDoS attack methods, and various other malicious tools. She further used the collected information at the tactical and operational levels.
Sarah obtained the required information from which of the following types of sharing partner?

  • A. Providers of threat actors
  • B. Providers of threat indicators
  • C. Providers of threat data feeds
  • D. Providers of comprehensive cyber-threat intelligence

正解: D

 

質問 12
Alice, an analyst, shared information with security operation managers and network operations center (NOC) staff for protecting the organizational resources against various threats. Information shared by Alice was highly technical and include threat actor TTPs, malware campaigns, tools used by threat actors, and so on.
Which of the following types of threat intelligence was shared by Alice?

  • A. Strategic threat intelligence
  • B. Technical threat intelligence
  • C. Operational threat intelligence
  • D. Tactical threat intelligence

正解: B

 

質問 13
In which of the following forms of bulk data collection are large amounts of data first collected from multiple sources in multiple formats and then processed to achieve threat intelligence?

  • A. Hybrid form
  • B. Unstructured form
  • C. Production form
  • D. Structured form

正解: B

 

質問 14
Jian is a member of the security team at Trinity, Inc. He was conducting a real-time assessment of system activities in order to acquire threat intelligence feeds. He acquired feeds from sources like honeynets, P2P monitoring. infrastructure, and application logs.
Which of the following categories of threat intelligence feed was acquired by Jian?

  • A. Internal intelligence feeds
  • B. CSV data feeds
  • C. Proactive surveillance feeds
  • D. External intelligence feeds

正解: A

 

質問 15
John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques.
What phase of the advanced persistent threat lifecycle is John currently in?

  • A. Persistence
  • B. Search and exfiltration
  • C. Expansion
  • D. Initial intrusion

正解: C

 

質問 16
Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information from a variety of sources. He wants to use this information to develop security policies to enhance the overall security posture of his organization.
Which of the following sharing platforms should be used by Kim?

  • A. OmniPeek
  • B. Blueliv threat exchange network
  • C. Cuckoo sandbox
  • D. PortDroid network analysis

正解: B

 

質問 17
Andrews and Sons Corp. has decided to share threat information among sharing partners. Garry, a threat analyst, working in Andrews and Sons Corp., has asked to follow a trust model necessary to establish trust between sharing partners. In the trust model used by him, the first organization makes use of a body of evidence in a second organization, and the level of trust between two organizations depends on the degree and quality of evidence provided by the first organization.
Which of the following types of trust model is used by Garry to establish the trust?

  • A. Mandated trust
  • B. Mediated trust
  • C. Direct historical trust
  • D. Validated trust

正解: D

 

質問 18
Henry. a threat intelligence analyst at ABC Inc., is working on a threat intelligence program. He was assigned to work on establishing criteria for prioritization of intelligence needs and requirements.
Which of the following considerations must be employed by Henry to prioritize intelligence requirements?

  • A. Develop a collection plan
  • B. Produce actionable data
  • C. Understand data reliability
  • D. Understand frequency and impact of a threat

正解: D

 

質問 19
Which of the following components refers to a node in the network that routes the traffic from a workstation to external command and control server and helps in identification of installed malware in the network?

  • A. Repeater
  • B. Network interface card (NIC)
  • C. Gateway
  • D. Hub

正解: C

 

質問 20
Enrage Tech Company hired Enrique, a security analyst, for performing threat intelligence analysis. While performing data collection process, he used a counterintelligence mechanism where a recursive DNS server is employed to perform interserver DNS communication and when a request is generated from any name server to the recursive DNS server, the recursive DNS servers log the responses that are received. Then it replicates the logged data and stores the data in the central database. Using these logs, he analyzed the malicious attempts that took place over DNS infrastructure.
Which of the following cyber counterintelligence (CCI) gathering technique has Enrique used for data collection?

  • A. Data collection through DNS zone transfer
  • B. Data collection through dynamic DNS (DDNS)
  • C. Data collection through passive DNS monitoring
  • D. Data collection through DNS interrogation

正解: D

 

質問 21
Steve works as an analyst in a UK-based firm. He was asked to perform network monitoring to find any evidence of compromise. During the network monitoring, he came to know that there are multiple logins from different locations in a short time span. Moreover, he also observed certain irregular log in patterns from locations where the organization does not have business relations. This resembles that somebody is trying to steal confidential information.
Which of the following key indicators of compromise does this scenario present?

  • A. Geographical anomalies
  • B. Unexpected patching of systems
  • C. Unusual activity through privileged user account
  • D. Unusual outbound network traffic

正解: C

 

質問 22
Moses, a threat intelligence analyst at InfoTec Inc., wants to find crucial information about the potential threats the organization is facing by using advanced Google search operators. He wants to identify whether any fake websites are hosted at the similar to the organization's URL.
Which of the following Google search queries should Moses use?

  • A. link: www.infothech.org
  • B. related: www.infothech.org
  • C. cache: www.infothech.org
  • D. info: www.infothech.org

正解: B

 

質問 23
An analyst is conducting threat intelligence analysis in a client organization, and during the information gathering process, he gathered information from the publicly available sources and analyzed to obtain a rich useful form of intelligence. The information source that he used is primarily used for national security, law enforcement, and for collecting intelligence required for business or strategic decision making.
Which of the following sources of intelligence did the analyst use to collect information?

  • A. SIGINT
  • B. OSINT
  • C. OPSEC
  • D. ISAC

正解: B

 

質問 24
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?

  • A. Distributed network attack
  • B. Advanced persistent attack
  • C. Zero-day attack
  • D. Active online attack

正解: C

 

質問 25
H&P, Inc. is a small-scale organization that has decided to outsource the network security monitoring due to lack of resources in the organization. They are looking for the options where they can directly incorporate threat intelligence into their existing network defense solutions.
Which of the following is the most cost-effective methods the organization can employ?

  • A. Look for an individual within the organization
  • B. Recruit data management solution provider
  • C. Recruit managed security service providers (MSSP)
  • D. Recruit the right talent

正解: C

 

質問 26
......


ECCouncil 312-85 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Overview of Threat Intelligence Feeds and Sources
  • Overview of Threat Intelligence Data Collection
トピック 2
  • Overview of Threat Intelligence Sharing
  • Requirements, Planning, Direction, and Review
トピック 3
  • Cyber Threats and Kill Chain Methodology
  • Understanding Cyber Kill Chain
トピック 4
  • Overview of Fine-Tuning Threat Analysis
  • Understanding Threat Intelligence Evaluation
トピック 5
  • Understanding Threat Intelligence Data Collection and Acquisition
  • Overview of Threat Intelligence Collection Management
トピック 6
  • Understanding Organization’s Current Threat Landscape
  • Reviewing Threat Intelligence Program
トピック 7
  • Understanding Threat Intelligence Sharing Platforms
  • Understanding Data Processing and Exploitation
トピック 8
  • Understanding Requirements Analysis
  • Building a Threat Intelligence Team
トピック 9
  • Overview of Threat Intelligence Integration
  • Overview of Threat Intelligence Reports
トピック 10
  • Overview of Intelligence Sharing Acts and Regulations
  • Understanding the Threat Analysis Process
トピック 11
  • Understanding Indicators of Compromise
  • Understanding Advanced Persistent Threats
トピック 12
  • Overview of Threat Intelligence Lifecycle and Frameworks
  • Introduction to Threat Intelligence

 

更新された検証済みの312-85問題集と解答で合格保証もしくは全額返金:https://www.jpntest.com/shiken/312-85-mondaishu

312-85のPDF問題とテストエンジンには50問があります:https://drive.google.com/open?id=1LStacSEzEnVgQrw_DTgRkY84tEvbG79l

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡