Home/ec council/Free ECcouncil 312-85 Actual Exam Questions

Free ECcouncil 312-85 Actual Exam Questions

The questions for this exam were last updated on January 7, 2026

Dumps Box (DumpsBox) offers up-to-date practice exam questions for 312-85 certification exam which are developed and validated by Ec-Council subject domain experts certified in ECcouncil 312-85 . These practice questions are update regularly as we keep an eye on any recent changes in 312-85 syllabus, and when there is update our team quickly adjusts the questions. This commitment to providing the best quality exam prep material to certification aspirants is what makes DumpsBox.com the best certification exam prep website. On top of that, our strong, yet strictly moderated, community based feedback keeps the content clean and current. Each question has helpful community discussion that provides it extra perspective and introduces helpful resources for better exam preparation. This also saves students from other outdated practice questions or illicit exam dumps that can have adverse affects on career. Browse through our ECcouncil 312-85 exam questions and pass your exam on first try.

Question No. 1
Daniel is a professional hacker whose aim is to attack a system to steal data and money for profit. He
performs hacking to obtain confidential data such as social security numbers, personally identifiable
information (PII) of an employee, and credit card information. After obtaining confidential data, he
further sells the information on the black market to make money.
Daniel comes under which of the following types of threat actor.
Select one option, then reveal solution.
Question No. 2
John, a professional hacker, is trying to perform APT attack on the target organization network. He
gains access to a single system of a target organization and tries to obtain administrative login
credentials to gain further access to the systems in the network using various techniques.
What phase of the advanced persistent threat lifecycle is John currently in?
Select one option, then reveal solution.
Question No. 3
Tracy works as a CISO in a large multinational company. She consumes threat intelligence to
understand the changing trends of cyber security. She requires intelligence to understand the current
business trends and make appropriate decisions regarding new technologies, security budget,
improvement of processes, and staff. The intelligence helps her in minimizing business risks and
protecting the new technology and business initiatives.
Identify the type of threat intelligence consumer is Tracy.
Select one option, then reveal solution.
Question No. 4
Alison, an analyst in an XYZ organization, wants to retrieve information about a company’s website
from the time of its inception as well as the removed information from the target website.
What should Alison do to get the information he needs.
Select one option, then reveal solution.
Question No. 5
Jame, a professional hacker, is trying to hack the confidential information of a target organization. He
identified the vulnerabilities in the target system and created a tailored deliverable malicious
payload using an exploit and a backdoor to send it to the victim.
Which of the following phases of cyber kill chain methodology is Jame executing?
Select one option, then reveal solution.
Question No. 6
A threat analyst wants to incorporate a requirement in the threat knowledge repository that provides
an ability to modify or delete past or irrelevant threat data.
Which of the following requirement must he include in the threat knowledge repository to fulfil his
needs?
Select one option, then reveal solution.
Question No. 7
Alice, a threat intelligence analyst at HiTech Cyber Solutions, wants to gather information for
identifying emerging threats to the organization and implement essential techniques to prevent their
systems and networks from such attacks. Alice is searching for online sources to obtain information
such as the method used to launch an attack, and techniques and tools used to perform an attack
and the procedures followed for covering the tracks after an attack.
Which of the following online sources should Alice use to gather such information?
Select one option, then reveal solution.
Question No. 8
An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery
locations in the rapidly changing network of compromised bots. In this particular technique, a single
domain name consists of multiple IP addresses.
Which of the following technique is used by the attacker?
Select one option, then reveal solution.
Question No. 9
Kathy wants to ensure that she shares threat intelligence containing sensitive information with the
appropriate audience. Hence, she used traffic light protocol (TLP).
Which TLP color would you signify that information should be shared only within a particular
community?
Select one option, then reveal solution.
Question No. 10
Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information
from a variety of sources. He wants to use this information to develop security policies to enhance
the overall security posture of his organization.
Which of the following sharing platforms should be used by Kim?
Select one option, then reveal solution.