Courseiva

312-85 · domain

Threat Hunting And Detection

Practise Certified Threat Intelligence Analyst (312-85) Threat Hunting And Detection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

23 questions5 easy10 medium8 hard

Focused practice

Practice Threat Hunting And Detection questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Threat Hunting And Detection

Threat Hunting And Detection questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Threat Hunting And Detection exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Threat Hunting And Detection questions (23)

Click any question to see the full explanation, or start a practice session above.

1

Which THREE techniques are commonly associated with the 'Execution' phase of the MITRE ATT&CK framework and should be prioritized in a threat hunt?

Hard
2

A threat hunter wants to identify unauthorized DNS tunneling. Which data point is most indicative of this activity?

Easy
3

When hunting for malicious DLL side-loading, which file property is most critical to verify?

Medium
4

Which TWO artifacts are most important when investigating a possible 'Fileless Malware' infection?

Medium
5

Which TWO command-line parameters are highly suspicious when observed with 'powershell.exe' in your telemetry?

Medium
6

Which tool is most effective for visualizing the parent-child process relationships during a threat hunt?

Medium
7

During an investigation, you observe suspicious PowerShell execution with the -EncodedCommand flag. Which log provider should you consult to see the decoded script block content?

Medium
8

You are hunting for unauthorized scheduled tasks. Which PowerShell cmdlet allows you to audit these tasks remotely across the enterprise?

Medium
9

An analyst is hunting for unauthorized network connections. Which port is commonly associated with SMB, frequently used for lateral movement (e.g., PSExec)?

Easy
10

A threat hunter is using Sysmon to identify potential process hollowing. Which Event ID should the analyst prioritize in their hunting query?

Easy
11

Which hunting methodology involves starting with a known adversary tactic and working backward to identify evidence in your logs?

Easy
12

To effectively hunt for C2 communication, which THREE indicators should be monitored in your proxy or firewall logs?

Hard
13

You are hunting for Cobalt Strike C2 using JA3/JA3S fingerprinting. If the JA3S value is unique for your environment and observed across multiple hosts, what does this suggest?

Hard
14

Which TWO log sources are most essential when hunting for adversary use of living-off-the-land binaries (LotL)?

Medium
15

While hunting for living-off-the-land (LotL) binaries, you identify suspicious use of 'certutil.exe'. What is the most likely malicious purpose for this utility?

Hard
16

Which TWO file integrity monitoring (FIM) events would be most useful to detect potential unauthorized persistence mechanisms?

Medium
17

An analyst is investigating potential persistence via WMI event subscriptions. Which WMI namespace should the hunter focus on for suspicious event consumers?

Medium
18

When hunting for credential dumping using Mimikatz, which process memory access pattern is the most common indicator?

Easy
19

When hunting for lateral movement, which THREE activities should be flagged as highly suspicious in a Windows environment?

Hard
20

Which THREE indicators are strong evidence of a 'Pass-the-Hash' attack occurring in your network?

Hard
21

While using ELK Stack for threat hunting, you need to identify beaconing behavior. Which aggregation function would best reveal periodicity in connection intervals?

Hard
22

When conducting a hunt for 'Golden Ticket' attacks, which attribute should be checked for anomalies in the Kerberos ticket?

Medium
23

A hunt for unusual Kerberos activity reveals an 'AS-REP Roasting' attack. What specific event indicator should the analyst look for in domain controller logs?

Hard

Frequently asked questions

What does the Threat Hunting And Detection domain cover on the 312-85 exam?
Threat Hunting And Detection questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 23 Threat Hunting And Detection questions in the 312-85 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Threat Hunting And Detection questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-ctia ECCOUNCIL-CTIA threat hunting and detection Practice Questions