312-85 Sample Questions & Answers
Collecting and processing threat-intelligence feeds and sources gets the biggest share, next to intelligence fundamentals and the lifecycle, attack frameworks like the Cyber Kill Chain, data analysis, reporting, threat hunting, and SOC integration.
Launch the full 312-85 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Introduction to Threat Intelligence · Intelligence Types
Case Study
A multinational logistics company, ShipFast, has recently experienced a series of targeted attacks. Their CTI team, led by an experienced analyst named Maria, is tasked with building a comprehensive threat profile of the adversary. Initial intelligence suggests the attacker is a sophisticated group focused on supply chain disruption. The company uses a hybrid cloud environment, with critical shipping and tracking data stored in AWS S3 buckets and on-premises databases.
Maria's team has collected various pieces of data: malware samples from compromised endpoints, network logs showing connections to unusual IP addresses, and OSINT from social media mentioning disruptions to ShipFast's competitors. The CISO needs a strategic report on the threat actor's identity and long-term intentions, while the SOC needs tactical intelligence to improve detections immediately. The team has access to a MISP instance, a SIEM, and standard malware analysis tools.
To meet the CISO's needs, Maria's team must produce a strategic intelligence product. Which element is MOST crucial to include in this report for the CISO and executive board?
Show answer & explanation
Correct answer: C
Strategic intelligence is forward-looking and focuses on high-level risks and business impact. For a CISO and executive board, the most critical information is not the technical minutiae but the 'so what?'—the adversary's goals, who they might be, and how their actions could affect the company's strategic objectives and standing in the market. This information drives decisions on security investment, risk management, and business strategy. The other options represent technical or tactical intelligence, which is vital for the SOC but not the primary focus for a strategic report.
- Question 2Intermediate
Threat Hunting and Detection · Threat Hunting Concepts
A threat hunter develops a hypothesis: 'An adversary is using WMI for lateral movement between workstations, evading our EDR's standard detections.' To test this, the hunter needs to search for specific event logs across the enterprise. Which Windows Event ID would be the MOST valuable to query for evidence of remote WMI command execution?
Show answer & explanation
Correct answer: B
While several events can be related, Event ID 4688 is the most direct and valuable for this hypothesis. When WMI is used to execute a command remotely, the WMI Provider Host (
WmiPrvSE.exe) on the target machine will spawn a new process to run that command. By filtering for Event ID 4688 where the parent process isWmiPrvSE.exeand the child process is something suspicious (likepowershell.exeorcmd.exe), the hunter can directly find evidence supporting the hypothesis. Event 4624 is too general, 4776 relates to credential validation, and 5156 is for network connections. - Question 3Beginner
Dissemination and Reporting of Intelligence · Sharing Threat Intelligence
True or False: In the context of the Traffic Light Protocol (TLP), information designated as TLP:AMBER can be shared outside the recipient's organization without any restrictions.
Show answer & explanation
Correct answer: B
This statement is false. TLP:AMBER indicates that information is limited to the recipient's organization and may only be shared with clients or customers who need to know in order to protect themselves or prevent further harm. It cannot be shared outside the organization without restrictions; any external sharing must be limited and purposeful.
- Question 4Beginner
Data Collection and Processing · OSINT Collection
A CTI analyst needs to collect information about the infrastructure associated with a suspected malicious domain. The goal is to find subdomains, historical IP addresses, and related SSL certificate information without directly interacting with the target domain. Which OSINT tool is specifically designed for this type of passive DNS and infrastructure analysis?
Show answer & explanation
Correct answer: C
VirusTotal is the best tool for this task among the options. Its domain and IP address reports provide extensive passive DNS data, historical WHOIS information, resolutions, detected URLs, and related SSL certificate details. Nmap is an active scanner. Maltego is a visualization and link analysis tool that often uses data from sources like VirusTotal. Wireshark is a network protocol analyzer for capturing live traffic, not for historical infrastructure analysis.
- Question 5Intermediate
Threat Intelligence in SOC Operations, Incident Response, and Risk Management · Threat Intelligence in Risk Management
A CTI team is briefing the organization's risk management committee. The intelligence indicates a high likelihood of a specific APT group targeting their industry within the next quarter. How does this threat intelligence directly support the risk management process?
Show answer & explanation
Correct answer: B
The core function of risk management is to identify, assess, and mitigate risks. A key formula is Risk = Likelihood x Impact. Threat intelligence provides evidence-based data that directly informs the 'Likelihood' component of this equation. By indicating a high probability of a specific threat, CTI allows the risk committee to move from a generic or assumed likelihood to a specific, data-driven one, resulting in a more accurate risk assessment and better-informed decisions on resource allocation for mitigation.
- Question 6Beginner
Cyber Threats and Attack Frameworks · Cyber Kill Chain
Which phase of the Cyber Kill Chain model represents the first opportunity for a defender to detect an adversary's malicious activity on the internal network, after an initial compromise has occurred?
Show answer & explanation
Correct answer: C
The 'Installation' phase is where the adversary establishes persistence on the victim's system, such as by installing a backdoor or creating a scheduled task. This is the first stage that definitively occurs on the internal network after the initial breach (Delivery and Exploitation). It provides a clear opportunity for defenders to detect malware installation, unauthorized software, or persistence mechanisms using host-based security controls like EDR or HIDS.
- Question 7Intermediate
Requirements, Planning, Direction, and Review · Planning Threat Intelligence Program
A CTI team lead is creating a charter for a new threat intelligence program. To ensure long-term success and relevance, the program's activities must be guided by stakeholder needs. Which of the following is the PRIMARY purpose of the 'Direction' phase of the CTI lifecycle?
Show answer & explanation
Correct answer: B
The 'Direction' phase (also known as Planning and Direction) is the foundational step where the CTI team translates the high-level intelligence requirements from stakeholders (like PIRs) into a concrete plan. This involves defining the scope, identifying specific questions to be answered, and creating a detailed collection plan that guides all subsequent activities. Without this translation, the team's efforts would be unfocused and unlikely to deliver value to the business.
- Question 8Intermediate
Introduction to Threat Intelligence · Intelligence Types
An analyst is investigating a phishing campaign and discovers the attacker is using a domain generation algorithm (DGA) to create new C2 domains daily. The security team wants to proactively block these domains. Which type of threat intelligence would be MOST effective for this purpose?
Show answer & explanation
Correct answer: C
Tactical threat intelligence focuses on the immediate tactics, techniques, and procedures (TTPs) of adversaries. Reverse-engineering the DGA to predict future C2 domains is a perfect example of tactical intelligence. It provides specific, actionable information (a list of domains to block) that the security team can use immediately to disrupt the attacker's operations. Strategic intelligence is high-level, operational is about campaigns, and technical is focused on specific indicators, but understanding the TTP (the DGA itself) is tactical.
- Question 9Beginner
Data Collection and Processing · Threat Intelligence Data Collection and Acquisition
A threat analyst needs to gather intelligence from a specific underground forum that requires vetting and building trust over time to gain access to private sub-forums. What type of intelligence collection discipline does this activity primarily fall under?
Show answer & explanation
Correct answer: D
This activity is a form of Human Intelligence (HUMINT). Although it occurs online, the core task involves interacting with people, building relationships, establishing credibility, and gaining trust to access information not otherwise available. This mirrors traditional HUMINT tradecraft. OSINT refers to publicly available information, TECHINT to analysis of equipment, and SIGINT to intercepted communications.
- Question 10Intermediate
Data Analysis · Threat Intelligence Tools
An analyst is writing a YARA rule to detect a specific variant of the Emotet malware. The malware uses a custom packing algorithm, making file hashes unreliable. However, the analyst has identified several unique strings within the unpacked malware's memory. Which section of the YARA rule is the appropriate place to define these unique strings?
Show answer & explanation
Correct answer: B
The
stringssection of a YARA rule is specifically designed for defining the patterns, such as text strings or hexadecimal byte sequences, that the rule will search for. Themetasection is for descriptive metadata, theruleline is for the name, and theconditionsection specifies the logic for when the rule should trigger based on the findings from thestringssection.
Ready for the real thing?
The full 312-85 simulator has every exam-style question, timed mode, and instant scoring.