Practice 312-85 Data Collection And Processing questions with full explanations on every answer.
Start practicing
Data Collection And Processing — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
When normalizing threat data using the STIX 2.1 standard, which field must be populated to define the 'type' of the observable for a file object?
2You are troubleshooting a feed ingestion failure in an OpenCTI platform where the connector logs show '403 Forbidden' during a HTTPS pull. What is the primary troubleshooting step?
3When collecting data from open-source intelligence (OSINT) sources, what is the primary risk associated with automated scraping without rate-limit awareness?
4You are configuring a TAXII 2.1 feed in a SIEM. You need to ensure that the collection process only retrieves high-confidence indicators. Where is this filter typically applied?
5You are using MISP to ingest a feed that provides indicators in CSV format. You need to map the 'src_ip' column to the appropriate MISP attribute type. Which mapping is most accurate for ensuring effective correlation?
6Which protocol is most commonly used for the automated transport of machine-readable threat intelligence, specifically designed to support the STIX format?
7While processing threat intelligence, you encounter an indicator containing a 'base64' encoded payload. Which action should be performed during normalization to maintain searchability?
8You are configuring a TAXII client to pull STIX 2.1 data from a commercial threat intelligence platform. During testing, the client reports a 406 Not Acceptable error. What is the most likely cause?
9Which of the following is a 'pull-based' method of threat intelligence data collection?
10In the context of STIX 2.1, what is the purpose of the 'relationship' object?
11Which of the following is an example of 'structured' threat intelligence data?
12You are integrating a dark web monitoring feed into your TIP. The data arrives as unstructured text. What is the most effective first step in the data processing pipeline?
13You are ingesting threat data into a TIP and notice that indicators lack 'TLP' (Traffic Light Protocol) markings. What is the standard industry procedure?
14A security analyst is validating a threat feed that uses JSON. Which tool is most appropriate for verifying that the JSON structure conforms to a specific schema?
15When deduplicating threat intelligence data, which unique identifier is most effective for comparing two different 'malware' objects?
16You are setting up a STIX-to-SIEM pipeline. The SIEM requires data in CSV format. What is the critical step in your data processing architecture?
17Which TWO of the following are common methods used to normalize threat data from disparate sources?
18Which THREE of the following are key components of a STIX 2.1 'Indicator' object?
19Which TWO of the following are recognized categories of threat intelligence sources?
20Which THREE of the following are considered challenges when ingesting threat intelligence feeds?
21Which TWO of the following are valid ways to improve the reliability of threat intelligence data?
22Which TWO of the following are common actions performed during the 'processing' phase of the threat intelligence lifecycle?
23Which THREE of the following are common attributes used to characterize an 'Observed Data' object in STIX 2.1?
24Which THREE of the following are critical steps when troubleshooting a failed TAXII 2.1 server connection?
The Data Collection And Processing domain covers the key concepts tested in this area of the 312-85 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-85 domains — no account required.
The Courseiva 312-85 question bank contains 24 questions in the Data Collection And Processing domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Data Collection And Processing domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included