Practice 312-85 Data Analysis questions with full explanations on every answer.
Start practicing
Data Analysis — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
When performing statistical analysis on threat actor TTP frequency, you identify a set of outliers that do not fit the normal distribution of observed incident timestamps. Which statistical measure should you apply to determine if these outliers are significant enough to warrant a change in threat modeling?
2You are performing a quantitative threat assessment on a high-value asset. You have a Threat Probability (P) of 0.2 and an Asset Impact (I) of $500,000. During the analysis, you find a new mitigation that reduces the probability by 50%. What is the new Annualized Loss Expectancy (ALE)?
3In the context of data analysis for CTI, what is the primary purpose of normalizing disparate log data from multiple SIEM sources?
4While conducting a threat modeling exercise using STRIDE, you are analyzing a cloud-based API gateway. You notice that authentication tokens are being logged in plain text in the debugging logs. Which threat category in STRIDE is most specifically violated here?
5In an ACH matrix, you have assigned values to the diagnostic evidence. You observe that a specific hypothesis has the lowest score. What does this indicate about the hypothesis?
6When utilizing the MITRE ATT&CK framework for data analysis, you identify that an actor is using 'DLL Side-Loading'. Which analytical technique should you apply to map this observation to the ATT&CK matrix?
7Which of the following is a primary benefit of using a 'Diamond Model' of intrusion analysis in your threat report?
8You are utilizing the Analysis of Competing Hypotheses (ACH) matrix to evaluate a potential APT intrusion. After populating your hypotheses and evidence, you notice that your primary hypothesis has a high number of 'consistent' evidence ratings but several 'contradictory' data points. How should you proceed according to standard ACH methodology?
9During a threat modeling session, you are analyzing a system's 'Attack Surface'. You decide to apply the 'Least Privilege' principle. Which specific analysis technique are you practicing to reduce potential pathways?
10What does a high 'CVSS' score indicate in the context of vulnerability data analysis?
11When conducting a 'Sensitivity Analysis' on your threat model, what are you attempting to determine?
12You are reviewing network traffic logs for potential C2 (Command and Control) beaconing. You decide to use a rolling average to smooth out the data. Why is this statistical technique useful in this scenario?
13Which of the following is a common pitfall when performing 'Trend Analysis' on threat data?
14You are analyzing an adversary's 'Infrastructure'. You note that they rotate IP addresses every 24 hours. Which analysis technique is most effective for mapping this persistent behavior?
15In threat modeling, what does the 'D' in DREAD risk assessment stand for?
16You are reviewing your organization's threat modeling process. Which TWO of the following are considered essential components to include when documenting a threat model?
17When conducting an Analysis of Competing Hypotheses (ACH), which TWO actions help mitigate cognitive bias in your conclusions?
18Which THREE factors should be considered when evaluating the reliability of threat intelligence data used in your analysis?
19When analyzing network traffic for C2 communication, which THREE anomalies are common indicators of malicious activity?
20Which TWO methods are effective for visualizing threat actor TTPs within a CTI report?
21Which TWO of the following are primary goals of conducting a threat modeling exercise on a new software application?
22When performing quantitative analysis, which THREE of the following are necessary to calculate the Annualized Loss Expectancy (ALE)?
23Which THREE data sources are typically analyzed when investigating an insider threat according to security behavior analytics?
The Data Analysis domain covers the key concepts tested in this area of the 312-85 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-85 domains — no account required.
The Courseiva 312-85 question bank contains 23 questions in the Data Analysis domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Data Analysis domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included