Courseiva

312-85 · domain

Cyber Threats And Attack Frameworks

Practise RAM questions covering identification, installation, speeds, dual-channel, and troubleshooting for the 312-85 exam.

24 questions4 easy13 medium7 hard

Focused practice

Practice Cyber Threats And Attack Frameworks questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Cyber Threats And Attack Frameworks

RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.

Identifying DDR3 vs DDR4 vs DDR5 physical and electrical differences

Matching RAM speed (MHz) to motherboard and CPU support

Calculating total memory capacity from module size and slots

Troubleshooting common RAM errors like beep codes and blue screens

Why learners struggle

Why Cyber Threats And Attack Frameworks questions are commonly missed

RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).

  • ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
  • ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
  • ·MHz vs CL — speed vs latency trade-offs in performance
  • ·Single-channel vs dual-channel — bandwidth impact misconception
  • ·ECC vs non-ECC — error correction support in servers vs desktops
  • ·32-bit vs 64-bit — maximum addressable RAM limit

Watch out for

Common Cyber Threats And Attack Frameworks exam traps

  • Confusing DDR3 and DDR4 notch positions and voltage requirements
  • Assuming dual-channel requires identical size modules only
  • Mixing ECC and non-ECC RAM in a single system
  • Forgetting that 32-bit OS limits usable RAM to 4 GB

Question index

All Cyber Threats And Attack Frameworks questions (24)

Click any question to see the full explanation, or start a practice session above.

1

Which of the following is considered an 'Indicator of Attack' (IOA) rather than an IOC?

Easy
2

Which TWO of the following actions are considered 'Defense Evasion' techniques?

Medium
3

An adversary uses a custom script to modify 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run'. Which MITRE ATT&CK technique is this?

Medium
4

Which TWO items are part of the 'Adversary' vertex in the Diamond Model?

Medium
5

Which THREE phases of the Cyber Kill Chain focus on the attacker's activities before reaching the target environment?

Medium
6

You are analyzing an APT threat group that consistently uses 'living-off-the-land' techniques. How should you approach identifying their presence using the MITRE ATT&CK framework?

Hard
7

You are assessing a company's incident response capability against the Cyber Kill Chain. If an attacker has successfully completed the 'Installation' phase, which defensive control should you have triggered?

Medium
8

You are mapping an adversary behavior to the MITRE ATT&CK framework. The attacker uses PowerShell to execute a Base64 encoded payload that downloads a secondary script. Under which Tactic should this specific execution behavior be primarily classified?

Medium
9

Which TWO of the following are considered 'Indicator of Compromise' (IOC) types?

Medium
10

When evaluating an adversary's TTPs, you notice they use 'Process Hollowing'. Which ATT&CK Tactic does this technique primarily support?

Medium
11

A security analyst is using the Diamond Model to document an incident. The analyst notes that the adversary used a specific Command and Control (C2) server IP address. In the context of the Diamond Model, where does this IP address belong?

Medium
12

You are performing threat hunting based on the Diamond Model. You identified a new Infrastructure node (IP). What is the logical next step in the Diamond Model analysis?

Hard
13

Which THREE of the following are primary components (vertices) of the Diamond Model of Intrusion Analysis?

Hard
14

During an investigation, you observe an attacker utilizing a custom-compiled Trojan that bypasses EDR detection. According to the Cyber Kill Chain, at which phase is this specific action of developing the custom tool occurring?

Hard
15

Which THREE MITRE ATT&CK tactics are commonly involved in an adversary's effort to maintain a presence on a compromised system?

Hard
16

An adversary is performing internal reconnaissance using 'net view' commands. In the MITRE ATT&CK framework, which technique ID maps to this behavior?

Medium
17

You are identifying Indicators of Compromise (IOCs) for an ongoing APT campaign. Which of the following is considered a Host-based IOC?

Medium
18

Which of the following best describes an Advanced Persistent Threat (APT)?

Easy
19

When applying the Cyber Kill Chain to an organization, which THREE phases are most effectively defended by network-level security controls?

Medium
20

Which phase of the Cyber Kill Chain is primarily mitigated by effective security awareness training for employees?

Easy
21

You observe an adversary using a legitimate VPN tunnel to communicate with their C2 server. Under the MITRE ATT&CK framework, which technique is this?

Hard
22

What is the primary purpose of the 'Actions on Objectives' phase in the Cyber Kill Chain?

Easy
23

An analyst is examining logs and finds a pattern of periodic heartbeat pings to an unknown external domain. Which MITRE ATT&CK tactic does this activity suggest?

Medium
24

Which THREE criteria are essential when evaluating the quality of an IOC for threat intelligence sharing?

Hard

Frequently asked questions

What does the Cyber Threats And Attack Frameworks domain cover on the 312-85 exam?
RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.
How many questions are in this domain?
This page lists all 24 Cyber Threats And Attack Frameworks questions in the 312-85 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cyber Threats And Attack Frameworks questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-ctia ECCOUNCIL-CTIA cyber threats and attack frameworks Practice Questions