20+ practice questions focused on Data Analysis — one of the most tested topics on the Certified Threat Intelligence Analyst (312-85) exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Data Analysis PracticeYou are tasked with evaluating the validity of a threat intelligence report provided by an external vendor. You choose to use ACH. What is the very first step you must take before populating the matrix?
Explanation: The first step in ACH is defining the research question or the problem statement clearly.
You are using the 'Kill Chain' model to analyze an incident. The logs show the adversary successfully gained credentials via phishing. Which phase does this correlate to?
Explanation: Weaponization occurs first, but credential harvesting via phishing falls squarely into the Delivery/Exploitation phase of the Kill Chain.
When performing statistical analysis on threat actor TTP frequency, you identify a set of outliers that do not fit the normal distribution of observed incident timestamps. Which statistical measure should you apply to determine if these outliers are significant enough to warrant a change in threat modeling?
Explanation: Standard deviation or Z-score is used to determine how many standard deviations an observation is from the mean.
You are performing a quantitative threat assessment on a high-value asset. You have a Threat Probability (P) of 0.2 and an Asset Impact (I) of $500,000. During the analysis, you find a new mitigation that reduces the probability by 50%. What is the new Annualized Loss Expectancy (ALE)?
Explanation: ALE = SLE x ARO. Since ALE = Probability x Impact, original ALE = 0.2 x $500,000 = $100,000. New probability is 0.1. 0.1 x $500,000 = $50,000.
In the context of data analysis for CTI, what is the primary purpose of normalizing disparate log data from multiple SIEM sources?
Explanation: Normalization allows for the correlation of disparate data types into a single schema for accurate analysis.
+15 more Data Analysis questions available
Practice all Data Analysis questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Data Analysis. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Data Analysis questions on the 312-85 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Data Analysis is tested as part of the Certified Threat Intelligence Analyst (312-85) blueprint. Practicing with targeted Data Analysis questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free 312-85 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Data Analysis is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Data Analysis practice session with instant scoring and detailed explanations.
Start Data Analysis Practice →