Practice 312-85 Intelligence Reporting And Dissemination questions with full explanations on every answer.
Start practicing
Intelligence Reporting And Dissemination — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Your organization uses a TIP (Threat Intelligence Platform) to ingest STIX feeds. You notice that the ingest process is failing specifically for feeds sourced from an older platform using STIX 1.2. Why is this occurring?
2You are troubleshooting a synchronization issue between two threat intelligence platforms. One platform is configured for TAXII 2.1 and the other is receiving the data but failing to parse the STIX 2.1 bundle. Which diagnostic step is most appropriate?
3An analyst is mapping internal incident data to STIX 2.1 objects. You need to link a specific threat actor to the infrastructure they recently utilized. Which object type should you use to link the 'Threat-Actor' object to the 'Infrastructure' object?
4You are drafting an executive threat report and need to adhere to the Traffic Light Protocol (TLP). The report contains sensitive information about an ongoing vulnerability in a zero-day exploit that could cause irreparable damage if leaked. Which TLP color should be applied?
5When setting up a TAXII 2.1 Collection in a commercial TIP, you are asked to provide a 'Collection ID'. What is the primary purpose of this identifier?
6You are configuring a TAXII 2.1 server to share threat indicators with a government partner. You need to ensure the connection enforces the transport-level security requirements for sensitive data exchange. Which setting must you verify in the TAXII configuration?
7You are integrating a new threat intel feed that provides 'Course of Action' (CoA) objects. What is the intended use of this STIX object type in an automated environment?
8A CISO asks for a report that provides a strategic outlook on the threat landscape for the upcoming quarter. What format is most appropriate for this type of audience?
9An organization wants to contribute intelligence to an ISAC (Information Sharing and Analysis Center). They need to ensure their sharing mechanism supports automated, near-real-time updates. Which standard should they adopt?
10When preparing a report for a SOC team, which metric is most important to include to prove the intelligence is actionable?
11Which regulatory framework should a company consider when sharing threat intelligence that contains PII (Personally Identifiable Information) with international partners?
12A threat intelligence report uses the Diamond Model for Intrusion Analysis. You are adding a new 'Victim' node. What information should you include to align with this model?
13You are analyzing an intelligence report provided in STIX 2.1 format. You find an 'Identity' object being used to attribute the campaign. What is the most common use of the 'Identity' object in this context?
14You are implementing a TIP and want to prioritize intelligence based on the source's reputation. Where should you configure this logic?
15You are mapping a threat report to the MITRE ATT&CK framework. You have identified that the attacker uses 'PowerShell' to execute commands. Which category should this be mapped to?
16You are disseminating a report. You want to ensure that the recipients understand the sensitivity of the information. What is the most effective way to communicate this standard?
17Which THREE of the following are valid Traffic Light Protocol (TLP) labels?
18Which TWO types of intelligence are primarily categorized as 'Tactical' in nature?
19Which THREE of the following are security best practices for managing a TAXII server?
20Which THREE of the following are core components of the STIX 2.1 Domain Object (SDO) structure?
21When setting up a TAXII 2.1 client, which THREE settings are mandatory for establishing a successful connection to a server?
22Which TWO of the following are necessary to include when creating a high-quality threat intelligence report for an operational team?
23Which TWO of the following are common challenges when sharing intelligence between organizations?
24Which THREE of the following are valid reasons to use the STIX 'Sighting' object?
25You are configuring a TAXII 2.1 client to consume feeds from an industry ISAC. You have successfully authenticated but are receiving empty response bodies for your collections. Which configuration setting should you verify in the TAXII client to ensure you are polling the correct resource path?
26You are drafting a STIX 2.1 'Observed-Data' object to report an IP address involved in a recent exfiltration event. To maintain standard compliance for automated ingestion, which property is mandatory to define the temporal scope of the observation?
27You are troubleshooting an issue where a SIEM cannot parse an incoming STIX 2.1 bundle. The bundle contains a 'Relationship' object linking a 'Malware' object to an 'Infrastructure' object. Which property within the 'Relationship' object must be verified to ensure the link type is recognized by the parser?
28When disseminating intelligence to C-level executives versus technical SOC analysts, you must adjust your reporting format. Which technique ensures compliance with intelligence cycle requirements for 'Actionable Intelligence'?
29A regulatory body requires your firm to report incidents using the 'Admiralty Code' for source reliability and information credibility. If you receive a report from a highly trusted partner that has been verified through multiple independent sources, which code should you assign?
30You are integrating a new threat intelligence platform (TIP). You need to define a 'Custom Object' in STIX 2.1 to track a specific internal project codename associated with threat actors. Which prefix must be used for the custom object name to ensure compatibility and avoid collisions?
31You are auditing your TAXII server configuration for data sharing compliance. Which TWO of the following items must be explicitly defined for each collection to ensure correct data governance and access control?
32When preparing a STIX 2.1 bundle for sharing via TAXII, which THREE of the following fields are strictly required for an 'Indicator' SDO to be considered 'well-formed'?
33You are selecting a format for sharing intelligence with a heterogeneous group of partners. Which THREE of the following are benefits of choosing STIX/TAXII over unstructured CSV/PDF reporting?
The Intelligence Reporting And Dissemination domain covers the key concepts tested in this area of the 312-85 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-85 domains — no account required.
The Courseiva 312-85 question bank contains 33 questions in the Intelligence Reporting And Dissemination domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Intelligence Reporting And Dissemination domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included