Skip to content

312-85 Certified Threat Intelligence Analyst (CTIA) Practice Questions

Prepare for 312-85 with more than an answer.

212 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$550 USD
Questions on the exam
50
Passing score
70%
Level
Specialist
Valid for
3 years
Domains covered on the exam 8
  1. Introduction to Threat Intelligence12%
  2. Cyber Threats and Attack Frameworks8%
  3. Requirements, Planning, Direction, and Review14%
  4. Data Collection and Processing24%
  5. Data Analysis16%
  6. Dissemination and Reporting of Intelligence14%
  7. Threat Hunting and Detection6%
  8. Threat Intelligence in SOC Operations, Incident Response, and Risk Management6%
  1. 1

    A retail company wants to evaluate its threat intelligence capability. An analyst determines the team is primarily consuming open-source and commercial threat feeds and using the indicators to populate blocklists on firewalls and proxies. The team performs very little analysis or correlation. According to standard CTI maturity models, which level does this capability represent?

    Show answer details

    Correct answer: B

    This level of capability is characteristic of a Basic or Ad-hoc maturity level. The focus is on reactive defense by consuming external data (indicators) with little to no internal analysis, context enrichment, or proactive measures. The program is essentially using threat data, not producing or analyzing threat intelligence. Higher maturity levels would involve data correlation, producing internal intelligence, and proactive threat hunting.

  2. 2

    A CTI team is tasked with assessing threats to their organization's AWS infrastructure. They need to collect and analyze logs related to API calls made by users, roles, and AWS services. Which AWS service should be the primary source for this data collection effort?

    Show answer details

    Correct answer: B

    AWS CloudTrail is the service that provides a detailed audit log of actions taken by a user, role, or an AWS service. It records API calls for your account and delivers log files to an Amazon S3 bucket. This makes it the essential source for understanding 'who did what, where, and when' within the AWS environment, which is fundamental for cloud threat intelligence and hunting. S3 is storage, GuardDuty is a threat detection service, and CloudWatch is for monitoring and logs, but CloudTrail specifically logs the API activity.

  3. 3

    True or False: The primary goal of threat hunting is to respond to alerts generated by automated security tools like SIEM or EDR.

    Show answer details

    Correct answer: B

    This statement is false. Threat hunting is a proactive security practice focused on searching for threats that have evaded existing, automated security defenses. It operates on the assumption that a breach has already occurred and is undetected. Responding to alerts is a reactive activity typically handled by a SOC or incident response team. Threat hunting begins where automated alerts end.

  4. 4

    Case Study

    A pharmaceutical research firm, BioGen Labs, has developed a groundbreaking new drug formula. The CTI team suspects that a state-sponsored actor, known as 'APT-Cure,' might attempt to steal this intellectual property. The team has limited resources and must focus its collection efforts efficiently. The CISO has established a clear PIR: 'What are the specific TTPs APT-Cure will use to target our research network and exfiltrate data?'

    To answer this PIR, the CTI team plans its collection strategy. They have access to commercial threat feeds, dark web monitoring services, and their internal network logs. The team knows that APT-Cure often uses custom malware and spear-phishing campaigns targeting senior researchers. Given the PIR and the adversary's known behavior, which of the following data collection activities should the team prioritize? (Select TWO)

    Show answer details

    Correct answer: B, D

  5. 5

    A security team has integrated its Threat Intelligence Platform (TIP) with its Security Orchestration, Automation, and Response (SOAR) platform. What is the primary benefit of this integration in a SOC environment?

    sequenceDiagram participant TIP participant SOAR participant Firewall participant SIEM TIP->>SOAR: New Malicious IP (Indicator) SOAR->>Firewall: API Call: Add Block Rule for IP SOAR->>SIEM: API Call: Create query to search for past activity Firewall-->>SOAR: Confirmation: Rule Added SIEM-->>SOAR: Query Results SOAR->>SOC Analyst: Create Ticket with findings and actions taken
    Show answer details

    Correct answer: B

    The integration of a TIP with a SOAR platform allows the SOC to move from manual response to automated workflows. As shown in the diagram, when the TIP receives a new, high-confidence indicator, it can trigger a playbook in the SOAR platform to automatically perform actions like blocking the IP on a firewall, searching for historical activity in the SIEM, and creating a ticket. This drastically reduces response times and frees up analysts from repetitive tasks.

  6. 6

    A financial services firm is building a new threat intelligence program. The CISO has requested a clear definition of the program's initial focus to secure executive buy-in. The primary goal is to proactively defend against threats targeting the firm's new mobile banking platform. Which of the following represents the MOST effective Priority Intelligence Requirement (PIR) for this initial phase?

    Show answer details

    Correct answer: C

    A strong Priority Intelligence Requirement (PIR) is specific, actionable, and tied to a key organizational priority. This option is the most effective because it clearly defines the threat actors of interest (those targeting mobile banking apps), the geographic scope (EU and North America), the specific intelligence needed (TTPs and indicators), and directly supports the CISO's goal of protecting the new platform. The other options are too broad and not directly tied to the specific, high-priority asset.

  7. 7

    A threat analyst is using the Diamond Model of Intrusion Analysis to map out an attack campaign. The analyst has identified the victim (a healthcare provider), the adversary's infrastructure (a specific VPS provider), and the capability (a known PowerShell-based malware). The analyst now needs to pivot their investigation to uncover other related campaigns. Which meta-feature of the Diamond Model would be MOST useful for this purpose?

    Show answer details

    Correct answer: D

    The Socio-Political meta-feature describes the adversary's intent and the victim's context (e.g., targeting healthcare during a pandemic). By understanding this context, the analyst can pivot to search for similar attacks against other healthcare providers or attacks motivated by the same geopolitical factors. This allows the analyst to link seemingly separate campaigns into a broader activity group, which is the goal of the pivot. The other options are less effective for expanding the investigation to other campaigns.

  8. 8

    A CTI team is automating the ingestion of threat indicators from various OSINT feeds using a Python script. They need to interact with the MISP API to add new attributes to existing events. The script has already authenticated and retrieved a specific event object. Which PyMISP function should the analyst use to add a new domain indicator to this event?

    Show answer details

    Correct answer: C

    The misp.add_named_attribute() function is the correct choice. It allows an analyst to add an attribute to a specific event by providing the event object (or its ID) and the attribute's type and value (e.g., 'domain', 'evil.com'). misp.new_event() creates a completely new event. misp.add_attribute() is a lower-level function that requires a manually constructed attribute object. misp.update_event() is used for modifying event-level metadata, not for adding attributes.

  9. 9

    During an incident response, an analyst receives a sensitive piece of intelligence from a trusted partner in an ISAC. The intelligence contains indicators of compromise for an active campaign but also includes details about the partner's internal detection capabilities. The analyst needs to share the IoCs with their internal SOC team for immediate action but must not reveal the source's capabilities. What is this process of modifying the intelligence before dissemination called?

    Show answer details

    Correct answer: B

    Sanitization is the process of removing sensitive information from intelligence products to protect sources, methods, or other confidential data before sharing it with a wider audience. In this scenario, the analyst is removing the partner's sensitive capabilities, which is a classic example of sanitization. Normalization is about formatting data consistently. Aggregation is combining data. Enrichment is adding context.

  10. 10

    A threat intelligence team is investigating a series of attacks against their organization. They have collected data suggesting two possible culprits: APT-A, a known state-sponsored group, and FIN-B, a financially motivated cybercrime gang. The team lead decides to use the Analysis of Competing Hypotheses (ACH) to rigorously evaluate the evidence. Which of the following actions are critical steps in the ACH process that the team must perform? (Select THREE)

    Show answer details

    Correct answer: A, C, D

Create an account to continue.