10 free EC-Council 312-85 CTIA v2 practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 88 questions. Work through them, then open each answer to check your reasoning.
Get all 88 questions (US$39) · Download these 10 as a PDF
Question 1
Daniel is a professional hacker whose aim is to attack a system to steal data and money for profit. He performs hacking to obtain confidential data such as social security numbers, personally identifiable information (PII) of an employee, and credit card information. After obtaining confidential data, he further sells the information on the black market to make money.
Daniel comes under which of the following types of threat actor.
Show answer and explanation
Correct answer: D. Organized hackers
Daniel engages in financially motivated cybercrime by stealing sensitive data and selling it on the black market for profit. This characterizes him as an organized hacker, part of a criminal enterprise focused on monetary gain through data theft and resale. Industrial spies work for competing organizations, state-sponsored hackers serve government interests, and insider threats originate from within organizations; none of these match Daniel's profile of external criminal activity for financial profit.
Why the other options are wrong
- A. Industrial spies conduct corporate espionage for competing businesses, not independent criminal data sales.
- B. State-sponsored hackers work on behalf of governments for political or strategic objectives, not personal profit.
- C. Insider threats originate from within an organization with internal access, whereas Daniel operates externally.
Question 2
An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery locations in the rapidly changing network of compromised bots. In this particular technique, a single domain name consists of multiple IP addresses.
Which of the following technique is used by the attacker?
Show answer and explanation
Correct answer: D. Fast-Flux DNS
Fast-Flux DNS is a technique where a single domain name is associated with multiple rapidly changing IP addresses, all pointing to compromised bot nodes. This provides camouflage by making it difficult to track and block phishing and malware delivery locations as they shift across the botnet infrastructure. DNS zone transfer involves copying entire DNS databases between servers, Dynamic DNS updates DNS records in real-time for legitimate purposes, and DNS interrogation queries DNS information, none specifically describe this botnet evasion method.
Why the other options are wrong
- A. DNS zone transfer is an administrative process for replicating DNS databases, not a camouflage technique for botnets.
- B. Dynamic DNS is used for legitimate purposes like updating DNS records for devices with changing IP addresses.
- C. DNS interrogation refers to querying DNS servers for information, not a technique for hiding malware delivery infrastructure.
Question 3
Kathy wants to ensure that she shares threat intelligence containing sensitive information with the appropriate audience. Hence, she used traffic light protocol (TLP).
Which TLP color would you signify that information should be shared only within a particular community?
Show answer and explanation
Correct answer: C. Green
Under the Traffic Light Protocol, TLP:GREEN means limited disclosure restricted to the community, so the information can circulate among peer organizations and partners in a sector or sharing community but not publicly. That matches Kathy's goal of releasing sensitive intelligence to a particular community of interest. TLP:GREEN is the correct marking for community-wide sharing.
Why the other options are wrong
- A. TLP:RED is the most restrictive marking and limits the information to the named individuals present at the exchange, with no further sharing at all.
- B. TLP:WHITE (now TLP:CLEAR) permits unlimited public distribution, which defeats the purpose of protecting sensitive intelligence.
- D. TLP:AMBER is narrower than GREEN because it confines the information to the recipient's own organization and, where needed, its clients, rather than releasing it to a wider community.
Question 4
Moses, a threat intelligence analyst at InfoTec Inc., wants to find crucial information about the potential threats the organization is facing by using advanced Google search operators. He wants to identify whether any fake websites are hosted at the similar to the organization’s URL.
Which of the following Google search queries should Moses use?
Show answer and explanation
Correct answer: A. related: www.infothech.org
The 'related:' operator in Google searches returns websites similar to a specified URL, making it ideal for identifying fake or lookalike websites hosted on domains similar to the organization's URL. This helps Moses discover potential typosquatting or phishing sites masquerading as InfoTec Inc. The 'info:' operator provides information about a specific URL, 'link:' finds pages linking to a URL, and 'cache:' retrieves cached versions, none specifically identify similar competing domains.
Why the other options are wrong
- B. The info: operator displays general information about a webpage, not similar or related websites.
- C. The link: operator finds pages that link to a specified URL, not similar competing domains.
- D. The cache: operator shows Google's cached version of a page, not related or similar websites.
Question 5
A team of threat intelligence analysts is performing threat analysis on malware, and each of them has come up with their own theory and evidence to support their theory on a given malware.
Now, to identify the most consistent theory out of all the theories, which of the following analytic processes must threat intelligence manager use?
Show answer and explanation
Correct answer: C. Analysis of competing hypotheses (ACH)
Analysis of Competing Hypotheses (ACH) is a structured analytical technique designed to evaluate multiple competing theories against evidence to identify which theory is most consistent and best supported. When multiple threat analysts present different theories with supporting evidence about malware behavior, ACH provides a systematic methodology to weigh and compare these hypotheses. Threat modeling examines attack vectors, Application Decomposition and Analysis breaks down software architecture, and Automated Technical Analysis uses tools to examine malware, none are designed to compare competing analytical theories.
Why the other options are wrong
- A. Threat modeling identifies potential attack scenarios and system vulnerabilities, not evaluates competing hypotheses.
- B. Application Decomposition and Analysis breaks down software components, not a method for comparing analytical theories.
- D. Automated Technical Analysis uses tools to examine malware behavior automatically, not a framework for evaluating competing theories.
Question 6
Miley, an analyst, wants to reduce the amount of collected data and make the storing and sharing process easy. She uses filtering, tagging, and queuing technique to sort out the relevant and structured data from the large amounts of unstructured data.
Which of the following techniques was employed by Miley?
Show answer and explanation
Correct answer: B. Normalization
Normalization is the process of converting unstructured or raw data into a structured, organized format using techniques like filtering, tagging, and queuing. This standardization makes data more useful, easier to store, and simpler to share across systems and teams. Miley's use of these specific techniques to organize and structure large amounts of unstructured data directly describes the normalization process. Sandboxing isolates environments, data visualization presents data graphically, and convenience sampling selects readily available data, none describe this data organization methodology.
Why the other options are wrong
- A. Sandboxing creates isolated environments for testing, not a technique for organizing and structuring raw data.
- C. Data visualization presents data through charts and graphics for interpretation, not the structural organization process Miley performed.
- D. Convenience sampling selects easily accessible data for analysis, not a method for organizing and structuring unstructured datasets.
Question 7
Bob, a threat analyst, works in an organization named TechTop. He was asked to collect intelligence to fulfil the needs and requirements of the Red Tam present within the organization.
Which of the following are the needs of a RedTeam?
Show answer and explanation
Correct answer: B. Intelligence on latest vulnerabilities, threat actors, and their tactics, techniques, and procedures (TTPs)
Red Teams conduct adversarial testing and simulations, requiring intelligence on the latest vulnerabilities, threat actors, and their tactics, techniques, and procedures (TTPs) to accurately emulate real-world threats and test organizational defenses. This current threat landscape information enables Red Teams to conduct realistic and effective security assessments. Intelligence on specific vulnerability attacks is too narrow, similar organization attacks focus on reactive intelligence rather than current threat capabilities, and strategic business risk intelligence serves strategic planning rather than Red Team operations.
Why the other options are wrong
- A. Intelligence on specific software vulnerabilities is narrow and reactive, not the broad threat landscape Red Teams need.
- C. Historical analysis of similar organization attacks serves defensive planning, not the current TTPs Red Teams need for realistic simulations.
- D. Strategic business risk intelligence informs executive decisions, not the technical threat actor capabilities Red Teams require.
Question 8
Michael, a threat analyst, works in an organization named TechTop, was asked to conduct a cyber-threat intelligence analysis. After obtaining information regarding threats, he has started analyzing the information and understanding the nature of the threats.
What stage of the cyber-threat intelligence is Michael currently in?
Show answer and explanation
Correct answer: C. Known unknowns
The intelligence analysis process progresses through stages of knowledge: Unknown unknowns are threats not yet recognized to exist, Known unknowns are identified gaps in understanding about known threat areas, Known knowns are established information already understood, and Unknowns unknown is not a standard stage. Michael has obtained information about threats and is now analyzing and understanding them, which represents the Known unknowns stage, he is aware that threats exist but is working to understand their specific nature, characteristics, and implications.
Why the other options are wrong
- A. Unknown unknowns represent threats the organization isn't aware exist, not the analytical stage of examining obtained threat information.
- B. This is not a recognized stage in the standard intelligence analysis framework.
- D. Known knowns represents already-understood and established information, not the active analysis phase Michael is currently conducting.
Question 9
Enrage Tech Company hired Enrique, a security analyst, for performing threat intelligence analysis. While performing data collection process, he used a counterintelligence mechanism where a recursive DNS server is employed to perform interserver DNS communication and when a request is generated from any name server to the recursive DNS server, the recursive DNS servers log the responses that are received. Then it replicates the logged data and stores the data in the central database. Using these logs, he analyzed the malicious attempts that took place over DNS infrastructure.
Which of the following cyber counterintelligence (CCI) gathering technique has Enrique used for data collection?
Show answer and explanation
Correct answer: A. Data collection through passive DNS monitoring
Passive DNS monitoring involves collecting and analyzing DNS queries and responses without actively interrogating DNS servers. The scenario describes a recursive DNS server logging responses from nameserver requests and replicating this data to a central database for analysis. This passive collection and logging of DNS traffic is the defining characteristic of passive DNS monitoring, which is a core counterintelligence technique for detecting malicious DNS activity and infrastructure without generating active queries.
Why the other options are wrong
- B. DNS interrogation is an active technique where specific DNS queries are sent to obtain information, not a passive logging and replication method.
- C. DNS zone transfer involves copying entire DNS zone files between nameservers, which is not what the recursive server logging mechanism described accomplishes.
- D. Dynamic DNS relates to mapping hostnames to changing IP addresses, not to logging DNS responses for threat analysis.
Question 10
John, a professional hacker, is trying to perform APT attack on the target organization network. He gains access to a single system of a target organization and tries to obtain administrative login credentials to gain further access to the systems in the network using various techniques.
What phase of the advanced persistent threat lifecycle is John currently in?
Show answer and explanation
Correct answer: C. Expansion
The expansion phase of an APT lifecycle occurs after initial system compromise, when the attacker works to move laterally and escalate privileges throughout the network. John has already gained access to a single system and is now attempting to obtain administrative credentials to access other systems in the network. This lateral movement and privilege escalation represents the expansion phase, where the attacker extends their foothold from the initially compromised system to other resources on the target network.
Why the other options are wrong
- A. Initial intrusion is the phase where the attacker first gains access to the network, which has already occurred.
- B. Search and exfiltration involves locating and stealing data, which comes after establishing broader network access.
- D. Persistence refers to maintaining access mechanisms for long-term presence, which occurs alongside but is distinct from the lateral movement and credential hunting described.
That was 10 of 88.
The full EC-Council 312-85 CTIA v2 pack has all 88 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
