312-85 · domain
Cyber Threats And Attack Frameworks
Practise RAM questions covering identification, installation, speeds, dual-channel, and troubleshooting for the 312-85 exam.
Focused practice
Practice Cyber Threats And Attack Frameworks questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Cyber Threats And Attack Frameworks
RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.
Identifying DDR3 vs DDR4 vs DDR5 physical and electrical differences
Matching RAM speed (MHz) to motherboard and CPU support
Calculating total memory capacity from module size and slots
Troubleshooting common RAM errors like beep codes and blue screens
Why learners struggle
Why Cyber Threats And Attack Frameworks questions are commonly missed
RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).
- ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
- ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
- ·MHz vs CL — speed vs latency trade-offs in performance
- ·Single-channel vs dual-channel — bandwidth impact misconception
- ·ECC vs non-ECC — error correction support in servers vs desktops
- ·32-bit vs 64-bit — maximum addressable RAM limit
Watch out for
Common Cyber Threats And Attack Frameworks exam traps
- ▸Confusing DDR3 and DDR4 notch positions and voltage requirements
- ▸Assuming dual-channel requires identical size modules only
- ▸Mixing ECC and non-ECC RAM in a single system
- ▸Forgetting that 32-bit OS limits usable RAM to 4 GB
Question index
All Cyber Threats And Attack Frameworks questions (24)
Click any question to see the full explanation, or start a practice session above.
Which of the following is considered an 'Indicator of Attack' (IOA) rather than an IOC?
Easy2Which TWO of the following actions are considered 'Defense Evasion' techniques?
Medium3An adversary uses a custom script to modify 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run'. Which MITRE ATT&CK technique is this?
Medium4Which TWO items are part of the 'Adversary' vertex in the Diamond Model?
Medium5Which THREE phases of the Cyber Kill Chain focus on the attacker's activities before reaching the target environment?
Medium6You are analyzing an APT threat group that consistently uses 'living-off-the-land' techniques. How should you approach identifying their presence using the MITRE ATT&CK framework?
Hard7You are assessing a company's incident response capability against the Cyber Kill Chain. If an attacker has successfully completed the 'Installation' phase, which defensive control should you have triggered?
Medium8You are mapping an adversary behavior to the MITRE ATT&CK framework. The attacker uses PowerShell to execute a Base64 encoded payload that downloads a secondary script. Under which Tactic should this specific execution behavior be primarily classified?
Medium9Which TWO of the following are considered 'Indicator of Compromise' (IOC) types?
Medium10When evaluating an adversary's TTPs, you notice they use 'Process Hollowing'. Which ATT&CK Tactic does this technique primarily support?
Medium11A security analyst is using the Diamond Model to document an incident. The analyst notes that the adversary used a specific Command and Control (C2) server IP address. In the context of the Diamond Model, where does this IP address belong?
Medium12You are performing threat hunting based on the Diamond Model. You identified a new Infrastructure node (IP). What is the logical next step in the Diamond Model analysis?
Hard13Which THREE of the following are primary components (vertices) of the Diamond Model of Intrusion Analysis?
Hard14During an investigation, you observe an attacker utilizing a custom-compiled Trojan that bypasses EDR detection. According to the Cyber Kill Chain, at which phase is this specific action of developing the custom tool occurring?
Hard15Which THREE MITRE ATT&CK tactics are commonly involved in an adversary's effort to maintain a presence on a compromised system?
Hard16An adversary is performing internal reconnaissance using 'net view' commands. In the MITRE ATT&CK framework, which technique ID maps to this behavior?
Medium17You are identifying Indicators of Compromise (IOCs) for an ongoing APT campaign. Which of the following is considered a Host-based IOC?
Medium18Which of the following best describes an Advanced Persistent Threat (APT)?
Easy19When applying the Cyber Kill Chain to an organization, which THREE phases are most effectively defended by network-level security controls?
Medium20Which phase of the Cyber Kill Chain is primarily mitigated by effective security awareness training for employees?
Easy21You observe an adversary using a legitimate VPN tunnel to communicate with their C2 server. Under the MITRE ATT&CK framework, which technique is this?
Hard22What is the primary purpose of the 'Actions on Objectives' phase in the Cyber Kill Chain?
Easy23An analyst is examining logs and finds a pattern of periodic heartbeat pings to an unknown external domain. Which MITRE ATT&CK tactic does this activity suggest?
Medium24Which THREE criteria are essential when evaluating the quality of an IOC for threat intelligence sharing?
HardOther domains
All 312-85 exam domains
Frequently asked questions
- What does the Cyber Threats And Attack Frameworks domain cover on the 312-85 exam?
- RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.
- How many questions are in this domain?
- This page lists all 24 Cyber Threats And Attack Frameworks questions in the 312-85 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cyber Threats And Attack Frameworks questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.