Courseiva
Requirements Planning Direction And ReviewhardMultiple ChoiceObjective-mapped

312-85 Requirements Planning Direction And Review Practice Question

An intelligence manager is reviewing the threat intelligence program's intelligence gap analysis. The analysis reveals that the team frequently fails to detect supply chain intrusions until late in the attack lifecycle. Which adjustments to the direction and planning phase should the manager implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Shift intelligence requirements to focus on initial access vectors, third-party supplier dependencies, and forums frequented by Initial Access Brokers (IABs)

Refining collection requirements and pivoting focus toward upstream threat indicators (such as supplier dependencies, third-party vendor risks, and initial access brokers) addresses late detection of supply chain intrusions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable all external threat intelligence feeds to reduce noise in the security operations center

    Why it's wrong here

    Disabling feeds would blind the organization to ongoing external threats rather than solving late-stage detection.

  • Reassign all malware reverse engineering tasks to helpdesk support personnel

    Why it's wrong here

    Helpdesk personnel lack the specialized skills required for malware reverse engineering.

  • Shift intelligence requirements to focus on initial access vectors, third-party supplier dependencies, and forums frequented by Initial Access Brokers (IABs)

    Why this is correct

    Shifting focus to IABs and third-party dependencies targets the early stages of supply chain intrusions, closing the intelligence gap.

  • Increase the budget for automated SIEM log retention from 30 days to 90 days

    Why it's wrong here

    Log retention duration is an infrastructure storage decision and does not directly address early-stage threat actor intelligence collection.

About these practice questions

One of 195 original 312-85 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This 312-85 practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 312-85 exam.