Practice 312-85 Cyber Threats And Attack Frameworks questions with full explanations on every answer.
Start practicing
Cyber Threats And Attack Frameworks — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
During an investigation, you observe an attacker utilizing a custom-compiled Trojan that bypasses EDR detection. According to the Cyber Kill Chain, at which phase is this specific action of developing the custom tool occurring?
2You are identifying Indicators of Compromise (IOCs) for an ongoing APT campaign. Which of the following is considered a Host-based IOC?
3What is the primary purpose of the 'Actions on Objectives' phase in the Cyber Kill Chain?
4A security analyst is using the Diamond Model to document an incident. The analyst notes that the adversary used a specific Command and Control (C2) server IP address. In the context of the Diamond Model, where does this IP address belong?
5You are analyzing an APT threat group that consistently uses 'living-off-the-land' techniques. How should you approach identifying their presence using the MITRE ATT&CK framework?
6When evaluating an adversary's TTPs, you notice they use 'Process Hollowing'. Which ATT&CK Tactic does this technique primarily support?
7An adversary is performing internal reconnaissance using 'net view' commands. In the MITRE ATT&CK framework, which technique ID maps to this behavior?
8You are mapping an adversary behavior to the MITRE ATT&CK framework. The attacker uses PowerShell to execute a Base64 encoded payload that downloads a secondary script. Under which Tactic should this specific execution behavior be primarily classified?
9You are assessing a company's incident response capability against the Cyber Kill Chain. If an attacker has successfully completed the 'Installation' phase, which defensive control should you have triggered?
10Which phase of the Cyber Kill Chain is primarily mitigated by effective security awareness training for employees?
11You observe an adversary using a legitimate VPN tunnel to communicate with their C2 server. Under the MITRE ATT&CK framework, which technique is this?
12Which of the following best describes an Advanced Persistent Threat (APT)?
13An analyst is examining logs and finds a pattern of periodic heartbeat pings to an unknown external domain. Which MITRE ATT&CK tactic does this activity suggest?
14Which of the following is considered an 'Indicator of Attack' (IOA) rather than an IOC?
15You are performing threat hunting based on the Diamond Model. You identified a new Infrastructure node (IP). What is the logical next step in the Diamond Model analysis?
16Which TWO of the following are considered 'Indicator of Compromise' (IOC) types?
17An adversary uses a custom script to modify 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run'. Which MITRE ATT&CK technique is this?
18Which THREE of the following are primary components (vertices) of the Diamond Model of Intrusion Analysis?
19When applying the Cyber Kill Chain to an organization, which THREE phases are most effectively defended by network-level security controls?
20Which THREE MITRE ATT&CK tactics are commonly involved in an adversary's effort to maintain a presence on a compromised system?
21Which TWO of the following actions are considered 'Defense Evasion' techniques?
22Which THREE criteria are essential when evaluating the quality of an IOC for threat intelligence sharing?
23Which TWO items are part of the 'Adversary' vertex in the Diamond Model?
24Which THREE phases of the Cyber Kill Chain focus on the attacker's activities before reaching the target environment?
The Cyber Threats And Attack Frameworks domain covers the key concepts tested in this area of the 312-85 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-85 domains — no account required.
The Courseiva 312-85 question bank contains 24 questions in the Cyber Threats And Attack Frameworks domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cyber Threats And Attack Frameworks domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included