312-85 Requirements Planning Direction And Review Practice Question
An intelligence manager is evaluating sources for a threat intelligence program during the planning phase. Which TWO criteria are critical when vetting a new external threat intelligence vendor or feed? (Choose TWO)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Relevance of the feed data to the organization's specific industry sector and geographic footprint
When vetting threat intelligence feeds or vendors, relevance to the organization's specific threat landscape and actionability of the data are paramount.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Relevance of the feed data to the organization's specific industry sector and geographic footprint
Why this is correct
Feeds must be relevant to the specific industry and region to be useful.
- ✗
The marketing budget of the threat intelligence vendor
Why it's wrong here
A vendor's marketing budget has no bearing on the technical quality or accuracy of their threat intelligence feed.
- ✗
Whether the vendor shares all threat data publicly on open-source social media platforms
Why it's wrong here
Public social media sharing is not a prerequisite or indicator of high-end threat intelligence vendor quality.
- ✓
Actionability of the intelligence provided, allowing security controls to be updated effectively
Why this is correct
Intelligence must be actionable, enabling defenders to update security controls or hunt for threats.
- ✗
The total number of unverified IP addresses included in the feed without regard to false positive rates
Why it's wrong here
High volume without context or low false positive rates introduces noise rather than quality intelligence.
About these practice questions
Courseiva writes every 312-85 question from scratch — 195 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This 312-85 practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 312-85 exam.