Courseiva

312-85 · topic practice

Threat Hunting And Detection practice questions

Practise Certified Threat Intelligence Analyst (312-85) Threat Hunting And Detection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Threat Hunting And Detection

What the exam tests

What to know about Threat Hunting And Detection

Threat Hunting And Detection questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Threat Hunting And Detection exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Threat Hunting And Detection questions

20 questions · select your answer, then reveal the explanation

When conducting a hunt for lateral movement using MITRE ATT&CK T1021.001 (Remote Desktop Protocol), which log source is most effective for detecting anomalous RDP connections?

While hunting for hidden network traffic, you identify anomalous 'Beacon' activity in the proxy logs. Which metric is the most effective way to filter out normal traffic noise?

When hunting for credential dumping using Mimikatz, which process memory access pattern is the most common indicator?

Question 4easymultiple choice
Read the full DNS explanation →

A threat hunter wants to identify unauthorized DNS tunneling. Which data point is most indicative of this activity?

You are hunting for Cobalt Strike C2 using JA3/JA3S fingerprinting. If the JA3S value is unique for your environment and observed across multiple hosts, what does this suggest?

An analyst is investigating potential persistence via WMI event subscriptions. Which WMI namespace should the hunter focus on for suspicious event consumers?

A threat hunter is using Sysmon to identify potential process hollowing. Which Event ID should the analyst prioritize in their hunting query?

During an investigation, you observe suspicious PowerShell execution with the -EncodedCommand flag. Which log provider should you consult to see the decoded script block content?

While using ELK Stack for threat hunting, you need to identify beaconing behavior. Which aggregation function would best reveal periodicity in connection intervals?

You are hunting for unauthorized scheduled tasks. Which PowerShell cmdlet allows you to audit these tasks remotely across the enterprise?

Which hunting methodology involves starting with a known adversary tactic and working backward to identify evidence in your logs?

When hunting for malicious DLL side-loading, which file property is most critical to verify?

While hunting for living-off-the-land (LotL) binaries, you identify suspicious use of 'certutil.exe'. What is the most likely malicious purpose for this utility?

Which tool is most effective for visualizing the parent-child process relationships during a threat hunt?

A hunt for unusual Kerberos activity reveals an 'AS-REP Roasting' attack. What specific event indicator should the analyst look for in domain controller logs?

An analyst is hunting for unauthorized network connections. Which port is commonly associated with SMB, frequently used for lateral movement (e.g., PSExec)?

When conducting a hunt for 'Golden Ticket' attacks, which attribute should be checked for anomalies in the Kerberos ticket?

Which TWO log sources are most essential when hunting for adversary use of living-off-the-land binaries (LotL)?

Which TWO artifacts are most important when investigating a possible 'Fileless Malware' infection?

Which THREE techniques are commonly associated with the 'Execution' phase of the MITRE ATT&CK framework and should be prioritized in a threat hunt?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Threat Hunting And Detection sessions

Start a Threat Hunting And Detection only practice session

Every question in these sessions is drawn from the Threat Hunting And Detection domain — nothing else.

Related practice questions

Related 312-85 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 312-85 exam test about Threat Hunting And Detection?
Threat Hunting And Detection questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Threat Hunting And Detection questions in a focused session?
Yes — the session launcher on this page draws every question from the Threat Hunting And Detection domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 312-85 topics?
Use the topic links above to move to related areas, or go back to the 312-85 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 312-85 exam covers. They are not copied from any real exam or dump site.