Practice 312-85 Threat Hunting And Detection questions with full explanations on every answer.
Start practicing
Threat Hunting And Detection — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
When hunting for credential dumping using Mimikatz, which process memory access pattern is the most common indicator?
2A threat hunter wants to identify unauthorized DNS tunneling. Which data point is most indicative of this activity?
3You are hunting for Cobalt Strike C2 using JA3/JA3S fingerprinting. If the JA3S value is unique for your environment and observed across multiple hosts, what does this suggest?
4An analyst is investigating potential persistence via WMI event subscriptions. Which WMI namespace should the hunter focus on for suspicious event consumers?
5A threat hunter is using Sysmon to identify potential process hollowing. Which Event ID should the analyst prioritize in their hunting query?
6During an investigation, you observe suspicious PowerShell execution with the -EncodedCommand flag. Which log provider should you consult to see the decoded script block content?
7While using ELK Stack for threat hunting, you need to identify beaconing behavior. Which aggregation function would best reveal periodicity in connection intervals?
8You are hunting for unauthorized scheduled tasks. Which PowerShell cmdlet allows you to audit these tasks remotely across the enterprise?
9Which hunting methodology involves starting with a known adversary tactic and working backward to identify evidence in your logs?
10When hunting for malicious DLL side-loading, which file property is most critical to verify?
11While hunting for living-off-the-land (LotL) binaries, you identify suspicious use of 'certutil.exe'. What is the most likely malicious purpose for this utility?
12Which tool is most effective for visualizing the parent-child process relationships during a threat hunt?
13A hunt for unusual Kerberos activity reveals an 'AS-REP Roasting' attack. What specific event indicator should the analyst look for in domain controller logs?
14An analyst is hunting for unauthorized network connections. Which port is commonly associated with SMB, frequently used for lateral movement (e.g., PSExec)?
15When conducting a hunt for 'Golden Ticket' attacks, which attribute should be checked for anomalies in the Kerberos ticket?
16Which TWO log sources are most essential when hunting for adversary use of living-off-the-land binaries (LotL)?
17Which TWO artifacts are most important when investigating a possible 'Fileless Malware' infection?
18Which THREE techniques are commonly associated with the 'Execution' phase of the MITRE ATT&CK framework and should be prioritized in a threat hunt?
19When hunting for lateral movement, which THREE activities should be flagged as highly suspicious in a Windows environment?
20To effectively hunt for C2 communication, which THREE indicators should be monitored in your proxy or firewall logs?
21Which TWO file integrity monitoring (FIM) events would be most useful to detect potential unauthorized persistence mechanisms?
22Which THREE indicators are strong evidence of a 'Pass-the-Hash' attack occurring in your network?
23Which TWO command-line parameters are highly suspicious when observed with 'powershell.exe' in your telemetry?
The Threat Hunting And Detection domain covers the key concepts tested in this area of the 312-85 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-85 domains — no account required.
The Courseiva 312-85 question bank contains 23 questions in the Threat Hunting And Detection domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Threat Hunting And Detection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included