Skip to main content

312-85 Real Exam Questions

EC-Council Certified Threat Intelligence Analyst (ECTIA)

49 questions available · Page 1 of 5

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques.

What phase of the advanced persistent threat lifecycle is John currently in?

  1. A

    Initial intrusion

  2. B

    Search and exfiltration

  3. C

    Expansion

  4. D

    Persistence

Show answer and explanation

Correct answer: C

Question 2 Single choice

A threat analyst obtains an intelligence related to a threat, where the data is sent in the form of a connection request from a remote host to the server. From this data, he obtains only the IP address of the source and destination but no contextual information. While processing this data, he obtains contextual information stating that multiple connection requests from different geo-locations are received by the server within a short time span, and as a result, the server is stressed and gradually its performance has reduced. He further performed analysis on the information based on the past and present experience and concludes the attack experienced by the client organization.

Which of the following attacks is performed on the client organization?

  1. A

    DHCP attacks

  2. B

    MAC spoofing attack

  3. C

    Distributed Denial-of-Service (DDoS) attack

  4. D

    Bandwidth attack

Show answer and explanation

Correct answer: C

Question 3 Single choice

Jian is a member of the security team at Trinity, Inc. He was conducting a real-time assessment of system activities in order to acquire threat intelligence feeds. He acquired feeds from sources like honeynets, P2P monitoring. infrastructure, and application logs.

Which of the following categories of threat intelligence feed was acquired by Jian?

  1. A

    Internal intelligence feeds

  2. B

    External intelligence feeds

  3. C

    CSV data feeds

  4. D

    Proactive surveillance feeds

Show answer and explanation

Correct answer: A

Question 4 Single choice

What is the correct sequence of steps involved in scheduling a threat intelligence program?

1. Review the project charter

2. Identify all deliverables

3. Identify the sequence of activities

4. Identify task dependencies

5. Develop the final schedule

6. Estimate duration of each activity

7. Identify and estimate resources for all activities

8. Define all activities

9. Build a work breakdown structure (WBS)

  1. A

    1-->9-->2-->8-->3-->7-->4-->6-->5

  2. B

    3-->4-->5-->2-->1-->9-->8-->7-->6

  3. C

    1-->2-->3-->4-->5-->6-->9-->8-->7

  4. D

    1-->2-->3-->4-->5-->6-->7-->8-->9

Show answer and explanation

Correct answer: A

Question 5 Single choice

An analyst is conducting threat intelligence analysis in a client organization, and during the information gathering process, he gathered information from the publicly available sources and analyzed to obtain a rich useful form of intelligence. The information source that he used is primarily used for national security, law enforcement, and for collecting intelligence required for business or strategic decision making.

Which of the following sources of intelligence did the analyst use to collect information?

  1. A

    OPSEC

  2. B

    ISAC

  3. C

    OSINT

  4. D

    SIGINT

Show answer and explanation

Correct answer: C

Question 6 Single choice

H&P, Inc. is a small-scale organization that has decided to outsource the network security monitoring due to lack of resources in the organization. They are looking for the options where they can directly incorporate threat intelligence into their existing network defense solutions.

Which of the following is the most cost-effective methods the organization can employ?

  1. A

    Recruit the right talent

  2. B

    Look for an individual within the organization

  3. C

    Recruit data management solution provider

  4. D

    Recruit managed security service providers (MSSP)

Show answer and explanation

Correct answer: D

Question 7 Single choice

Tracy works as a CISO in a large multinational company. She consumes threat intelligence to understand the changing trends of cyber security. She requires intelligence to understand the current business trends and make appropriate decisions regarding new technologies, security budget, improvement of processes, and staff. The intelligence helps her in minimizing business risks and protecting the new technology and business initiatives.

Identify the type of threat intelligence consumer is Tracy.

  1. A

    Tactical users

  2. B

    Strategic users

  3. C

    Operational users

  4. D

    Technical users

Show answer and explanation

Correct answer: B

Question 8 Single choice

Jim works as a security analyst in a large multinational company. Recently, a group of hackers penetrated into their organizational network and used a data staging technique to collect sensitive data. They collected all sorts of sensitive data about the employees and customers, business tactics of the organization, financial information, network infrastructure information and so on.

What should Jim do to detect the data staging before the hackers exfiltrate from the network?

  1. A

    Jim should identify the attack at an initial stage by checking the content of the user agent field.

  2. B

    Jim should analyze malicious DNS requests, DNS payload, unspecified domains, and destination of
    DNS requests.

  3. C

    Jim should monitor network traffic for malicious file transfers, file integrity monitoring, and event logs.

  4. D

    Jim should identify the web shell running in the network by analyzing server access, error logs, suspicious strings indicating encoding, user agent strings, and so on.

Show answer and explanation

Correct answer: C

Question 9 Single choice

An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery locations in the rapidly changing network of compromised bots. In this particular technique, a single domain name consists of multiple IP addresses.

Which of the following technique is used by the attacker?

  1. A

    DNS zone transfer

  2. B

    Dynamic DNS

  3. C

    DNS interrogation

  4. D

    Fast-Flux DNS

Show answer and explanation

Correct answer: D

Question 10 Single choice

Miley, an analyst, wants to reduce the amount of collected data and make the storing and sharing process easy. She uses filtering, tagging, and queuing technique to sort out the relevant and structured data from the large amounts of unstructured data.

Which of the following techniques was employed by Miley?

  1. A

    Sandboxing

  2. B

    Normalization

  3. C

    Data visualization

  4. D

    Convenience sampling

Show answer and explanation

Correct answer: B