Courseiva

312-85 · topic practice

Cyber Threats And Attack Frameworks practice questions

Practise RAM questions covering identification, installation, speeds, dual-channel, and troubleshooting for the 312-85 exam.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Cyber Threats And Attack Frameworks

What the exam tests

What to know about Cyber Threats And Attack Frameworks

RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.

Identifying DDR3 vs DDR4 vs DDR5 physical and electrical differences

Matching RAM speed (MHz) to motherboard and CPU support

Calculating total memory capacity from module size and slots

Troubleshooting common RAM errors like beep codes and blue screens

Why learners struggle

Why Cyber Threats And Attack Frameworks questions are commonly missed

RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).

  • ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
  • ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
  • ·MHz vs CL — speed vs latency trade-offs in performance
  • ·Single-channel vs dual-channel — bandwidth impact misconception
  • ·ECC vs non-ECC — error correction support in servers vs desktops
  • ·32-bit vs 64-bit — maximum addressable RAM limit

Watch out for

Common Cyber Threats And Attack Frameworks exam traps

  • Confusing DDR3 and DDR4 notch positions and voltage requirements
  • Assuming dual-channel requires identical size modules only
  • Mixing ECC and non-ECC RAM in a single system
  • Forgetting that 32-bit OS limits usable RAM to 4 GB

Practice set

Cyber Threats And Attack Frameworks questions

20 questions · select your answer, then reveal the explanation

In the Diamond Model, the 'Technology' axis (often associated with the Capability-Infrastructure edge) is used to track what specifically?

During an investigation, you observe an attacker utilizing a custom-compiled Trojan that bypasses EDR detection. According to the Cyber Kill Chain, at which phase is this specific action of developing the custom tool occurring?

You are identifying Indicators of Compromise (IOCs) for an ongoing APT campaign. Which of the following is considered a Host-based IOC?

What is the primary purpose of the 'Actions on Objectives' phase in the Cyber Kill Chain?

A security analyst is using the Diamond Model to document an incident. The analyst notes that the adversary used a specific Command and Control (C2) server IP address. In the context of the Diamond Model, where does this IP address belong?

You are analyzing an APT threat group that consistently uses 'living-off-the-land' techniques. How should you approach identifying their presence using the MITRE ATT&CK framework?

When evaluating an adversary's TTPs, you notice they use 'Process Hollowing'. Which ATT&CK Tactic does this technique primarily support?

An adversary is performing internal reconnaissance using 'net view' commands. In the MITRE ATT&CK framework, which technique ID maps to this behavior?

You are mapping an adversary behavior to the MITRE ATT&CK framework. The attacker uses PowerShell to execute a Base64 encoded payload that downloads a secondary script. Under which Tactic should this specific execution behavior be primarily classified?

You are assessing a company's incident response capability against the Cyber Kill Chain. If an attacker has successfully completed the 'Installation' phase, which defensive control should you have triggered?

Which phase of the Cyber Kill Chain is primarily mitigated by effective security awareness training for employees?

Question 12hardmultiple choice
Read the full VPN explanation →

You observe an adversary using a legitimate VPN tunnel to communicate with their C2 server. Under the MITRE ATT&CK framework, which technique is this?

Which of the following best describes an Advanced Persistent Threat (APT)?

An analyst is examining logs and finds a pattern of periodic heartbeat pings to an unknown external domain. Which MITRE ATT&CK tactic does this activity suggest?

Which of the following is considered an 'Indicator of Attack' (IOA) rather than an IOC?

You are performing threat hunting based on the Diamond Model. You identified a new Infrastructure node (IP). What is the logical next step in the Diamond Model analysis?

Which TWO of the following are considered 'Indicator of Compromise' (IOC) types?

An adversary uses a custom script to modify 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run'. Which MITRE ATT&CK technique is this?

Which THREE of the following are primary components (vertices) of the Diamond Model of Intrusion Analysis?

When applying the Cyber Kill Chain to an organization, which THREE phases are most effectively defended by network-level security controls?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cyber Threats And Attack Frameworks sessions

Start a Cyber Threats And Attack Frameworks only practice session

Every question in these sessions is drawn from the Cyber Threats And Attack Frameworks domain — nothing else.

Related practice questions

Related 312-85 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 312-85 exam test about Cyber Threats And Attack Frameworks?
RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cyber Threats And Attack Frameworks questions in a focused session?
Yes — the session launcher on this page draws every question from the Cyber Threats And Attack Frameworks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 312-85 topics?
Use the topic links above to move to related areas, or go back to the 312-85 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 312-85 exam covers. They are not copied from any real exam or dump site.