[2022年02月14日]312-85サンプルには正確で更新された問題 [Q19-Q37]

Share

[2022年02月14日]312-85サンプルには正確で更新された問題

312-85試験情報と無料練習テスト

質問 19
Joe works as a threat intelligence analyst with Xsecurity Inc. He is assessing the TI program by comparing the project results with the original objectives by reviewing project charter. He is also reviewing the list of expected deliverables to ensure that each of those is delivered to an acceptable level of quality.
Identify the activity that Joe is performing to assess a TI program's success or failure.

  • A. Identifying areas of further improvement
  • B. Determining the costs and benefits associated with the program
  • C. Conducting a gap analysis
  • D. Determining the fulfillment of stakeholders

正解: C

 

質問 20
Michael, a threat analyst, works in an organization named TechTop, was asked to conduct a cyber-threat intelligence analysis. After obtaining information regarding threats, he has started analyzing the information and understanding the nature of the threats.
What stage of the cyber-threat intelligence is Michael currently in?

  • A. Known knowns
  • B. Known unknowns
  • C. Unknowns unknown
  • D. Unknown unknowns

正解: B

 

質問 21
Andrews and Sons Corp. has decided to share threat information among sharing partners. Garry, a threat analyst, working in Andrews and Sons Corp., has asked to follow a trust model necessary to establish trust between sharing partners. In the trust model used by him, the first organization makes use of a body of evidence in a second organization, and the level of trust between two organizations depends on the degree and quality of evidence provided by the first organization.
Which of the following types of trust model is used by Garry to establish the trust?

  • A. Mandated trust
  • B. Mediated trust
  • C. Direct historical trust
  • D. Validated trust

正解: D

 

質問 22
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?

  • A. Distributed network attack
  • B. Advanced persistent attack
  • C. Zero-day attack
  • D. Active online attack

正解: C

 

質問 23
Which of the following types of threat attribution deals with the identification of the specific person, society, or a country sponsoring a well-planned and executed intrusion or attack over its target?

  • A. Nation-state attribution
  • B. Intrusion-set attribution
  • C. True attribution
  • D. Campaign attribution

正解: C

 

質問 24
Jim works as a security analyst in a large multinational company. Recently, a group of hackers penetrated into their organizational network and used a data staging technique to collect sensitive dat a. They collected all sorts of sensitive data about the employees and customers, business tactics of the organization, financial information, network infrastructure information and so on.
What should Jim do to detect the data staging before the hackers exfiltrate from the network?

  • A. Jim should analyze malicious DNS requests, DNS payload, unspecified domains, and destination of DNS requests.
  • B. Jim should monitor network traffic for malicious file transfers, file integrity monitoring, and event logs.
  • C. Jim should identify the web shell running in the network by analyzing server access, error logs, suspicious strings indicating encoding, user agent strings, and so on.
  • D. Jim should identify the attack at an initial stage by checking the content of the user agent field.

正解: B

 

質問 25
SecurityTech Inc. is developing a TI plan where it can drive more advantages in less funds. In the process of selecting a TI platform, it wants to incorporate a feature that ranks elements such as intelligence sources, threat actors, attacks, and digital assets of the organization, so that it can put in more funds toward the resources which are critical for the organization's security.
Which of the following key features should SecurityTech Inc. consider in their TI plan for selecting the TI platform?

  • A. Search
  • B. Open
  • C. Scoring
  • D. Workflow

正解: C

 

質問 26
During the process of threat intelligence analysis, John, a threat analyst, successfully extracted an indication of adversary's information, such as Modus operandi, tools, communication channels, and forensics evasion strategies used by adversaries.
Identify the type of threat intelligence analysis is performed by John.

  • A. Tactical threat intelligence analysis
  • B. Technical threat intelligence analysis
  • C. Strategic threat intelligence analysis
  • D. Operational threat intelligence analysis

正解: A

 

質問 27
Karry, a threat analyst at an XYZ organization, is performing threat intelligence analysis. During the data collection phase, he used a data collection method that involves no participants and is purely based on analysis and observation of activities and processes going on within the local boundaries of the organization.
Identify the type data collection method used by the Karry.

  • A. Raw data collection
  • B. Active data collection
  • C. Exploited data collection
  • D. Passive data collection

正解: D

 

質問 28
H&P, Inc. is a small-scale organization that has decided to outsource the network security monitoring due to lack of resources in the organization. They are looking for the options where they can directly incorporate threat intelligence into their existing network defense solutions.
Which of the following is the most cost-effective methods the organization can employ?

  • A. Look for an individual within the organization
  • B. Recruit data management solution provider
  • C. Recruit managed security service providers (MSSP)
  • D. Recruit the right talent

正解: C

 

質問 29
Daniel is a professional hacker whose aim is to attack a system to steal data and money for profit. He performs hacking to obtain confidential data such as social security numbers, personally identifiable information (PII) of an employee, and credit card information. After obtaining confidential data, he further sells the information on the black market to make money.
Daniel comes under which of the following types of threat actor.

  • A. Industrial spies
  • B. Organized hackers
  • C. Insider threat
  • D. State-sponsored hackers

正解: B

 

質問 30
Tracy works as a CISO in a large multinational company. She consumes threat intelligence to understand the changing trends of cyber security. She requires intelligence to understand the current business trends and make appropriate decisions regarding new technologies, security budget, improvement of processes, and staff. The intelligence helps her in minimizing business risks and protecting the new technology and business initiatives.
Identify the type of threat intelligence consumer is Tracy.

  • A. Strategic users
  • B. Tactical users
  • C. Operational users
  • D. Technical users

正解: A

 

質問 31
In which of the following forms of bulk data collection are large amounts of data first collected from multiple sources in multiple formats and then processed to achieve threat intelligence?

  • A. Hybrid form
  • B. Unstructured form
  • C. Production form
  • D. Structured form

正解: B

 

質問 32
A threat analyst obtains an intelligence related to a threat, where the data is sent in the form of a connection request from a remote host to the server. From this data, he obtains only the IP address of the source and destination but no contextual information. While processing this data, he obtains contextual information stating that multiple connection requests from different geo-locations are received by the server within a short time span, and as a result, the server is stressed and gradually its performance has reduced. He further performed analysis on the information based on the past and present experience and concludes the attack experienced by the client organization.
Which of the following attacks is performed on the client organization?

  • A. Distributed Denial-of-Service (DDoS) attack
  • B. DHCP attacks
  • C. MAC spoofing attack
  • D. Bandwidth attack

正解: A

 

質問 33
Alice, a threat intelligence analyst at HiTech Cyber Solutions, wants to gather information for identifying emerging threats to the organization and implement essential techniques to prevent their systems and networks from such attacks. Alice is searching for online sources to obtain information such as the method used to launch an attack, and techniques and tools used to perform an attack and the procedures followed for covering the tracks after an attack.
Which of the following online sources should Alice use to gather such information?

  • A. Financial services
  • B. Hacking forums
  • C. Job sites
  • D. Social network settings

正解: B

 

質問 34
Tim is working as an analyst in an ABC organization. His organization had been facing many challenges in converting the raw threat intelligence data into meaningful contextual information. After inspection, he found that it was due to noise obtained from misrepresentation of data from huge data collections. Hence, it is important to clean the data before performing data analysis using techniques such as data reduction. He needs to choose an appropriate threat intelligence framework that automatically performs data collection, filtering, and analysis for his organization.
Which of the following threat intelligence frameworks should he choose to perform such task?

  • A. Threat grid
  • B. TC complete
  • C. SIGVERIF
  • D. HighCharts

正解: B

 

質問 35
Bob, a threat analyst, works in an organization named TechTop. He was asked to collect intelligence to fulfil the needs and requirements of the Red Tam present within the organization.
Which of the following are the needs of a RedTeam?

  • A. Intelligence on latest vulnerabilities, threat actors, and their tactics, techniques, and procedures (TTPs)
  • B. Intelligence that reveals risks related to various strategic business decisions
  • C. Intelligence related to increased attacks targeting a particular software or operating system vulnerability
  • D. Intelligence extracted latest attacks analysis on similar organizations, which includes details about latest threats and TTPs

正解: A

 

質問 36
A network administrator working in an ABC organization collected log files generated by a traffic monitoring system, which may not seem to have useful information, but after performing proper analysis by him, the same information can be used to detect an attack in the network.
Which of the following categories of threat information has he collected?

  • A. Low-level data
  • B. Advisories
  • C. Strategic reports
  • D. Detection indicators

正解: D

 

質問 37
......

合格させるECCouncil 312-85プレミアムお試しセットテストエンジンPDFで無料問題集セット:https://www.passtest.jp/ECCouncil/312-85-shiken.html

2022年最新の実際に出る312-85問題集テストエンジン試験問題はここにある:https://drive.google.com/open?id=1aM6NexJxYexy8q2SN1inBofkl6aXALBH