312-85 · domain
Data Analysis
Practise Certified Threat Intelligence Analyst (312-85) Data Analysis practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Data Analysis questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Data Analysis
Data Analysis questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Data Analysis exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Data Analysis questions (23)
Click any question to see the full explanation, or start a practice session above.
When utilizing the MITRE ATT&CK framework for data analysis, you identify that an actor is using 'DLL Side-Loading'. Which analytical technique should you apply to map this observation to the ATT&CK matrix?
Medium2Which TWO of the following are primary goals of conducting a threat modeling exercise on a new software application?
Medium3In threat modeling, what does the 'D' in DREAD risk assessment stand for?
Easy4You are utilizing the Analysis of Competing Hypotheses (ACH) matrix to evaluate a potential APT intrusion. After populating your hypotheses and evidence, you notice that your primary hypothesis has a high number of 'consistent' evidence ratings but several 'contradictory' data points. How should you proceed according to standard ACH methodology?
Medium5When performing statistical analysis on threat actor TTP frequency, you identify a set of outliers that do not fit the normal distribution of observed incident timestamps. Which statistical measure should you apply to determine if these outliers are significant enough to warrant a change in threat modeling?
Medium6When analyzing network traffic for C2 communication, which THREE anomalies are common indicators of malicious activity?
Hard7You are performing a quantitative threat assessment on a high-value asset. You have a Threat Probability (P) of 0.2 and an Asset Impact (I) of $500,000. During the analysis, you find a new mitigation that reduces the probability by 50%. What is the new Annualized Loss Expectancy (ALE)?
Hard8When performing quantitative analysis, which THREE of the following are necessary to calculate the Annualized Loss Expectancy (ALE)?
Hard9In the context of data analysis for CTI, what is the primary purpose of normalizing disparate log data from multiple SIEM sources?
Easy10Which TWO methods are effective for visualizing threat actor TTPs within a CTI report?
Medium11Which of the following is a primary benefit of using a 'Diamond Model' of intrusion analysis in your threat report?
Easy12You are reviewing your organization's threat modeling process. Which TWO of the following are considered essential components to include when documenting a threat model?
Medium13Which THREE data sources are typically analyzed when investigating an insider threat according to security behavior analytics?
Hard14In an ACH matrix, you have assigned values to the diagnostic evidence. You observe that a specific hypothesis has the lowest score. What does this indicate about the hypothesis?
Hard15What does a high 'CVSS' score indicate in the context of vulnerability data analysis?
Easy16During a threat modeling session, you are analyzing a system's 'Attack Surface'. You decide to apply the 'Least Privilege' principle. Which specific analysis technique are you practicing to reduce potential pathways?
Hard17While conducting a threat modeling exercise using STRIDE, you are analyzing a cloud-based API gateway. You notice that authentication tokens are being logged in plain text in the debugging logs. Which threat category in STRIDE is most specifically violated here?
Hard18When conducting a 'Sensitivity Analysis' on your threat model, what are you attempting to determine?
Hard19You are reviewing network traffic logs for potential C2 (Command and Control) beaconing. You decide to use a rolling average to smooth out the data. Why is this statistical technique useful in this scenario?
Medium20When conducting an Analysis of Competing Hypotheses (ACH), which TWO actions help mitigate cognitive bias in your conclusions?
Hard21You are analyzing an adversary's 'Infrastructure'. You note that they rotate IP addresses every 24 hours. Which analysis technique is most effective for mapping this persistent behavior?
Medium22Which THREE factors should be considered when evaluating the reliability of threat intelligence data used in your analysis?
Medium23Which of the following is a common pitfall when performing 'Trend Analysis' on threat data?
EasyOther domains
All 312-85 exam domains
Frequently asked questions
- What does the Data Analysis domain cover on the 312-85 exam?
- Data Analysis questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 23 Data Analysis questions in the 312-85 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Data Analysis questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.