312-85 · domain
Data Collection And Processing
Practise Certified Threat Intelligence Analyst (312-85) Data Collection And Processing practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Data Collection And Processing questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Data Collection And Processing
Data Collection And Processing questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Data Collection And Processing exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Data Collection And Processing questions (24)
Click any question to see the full explanation, or start a practice session above.
Which THREE of the following are common attributes used to characterize an 'Observed Data' object in STIX 2.1?
Hard2You are troubleshooting a feed ingestion failure in an OpenCTI platform where the connector logs show '403 Forbidden' during a HTTPS pull. What is the primary troubleshooting step?
Hard3You are configuring a TAXII 2.1 feed in a SIEM. You need to ensure that the collection process only retrieves high-confidence indicators. Where is this filter typically applied?
Medium4While processing threat intelligence, you encounter an indicator containing a 'base64' encoded payload. Which action should be performed during normalization to maintain searchability?
Hard5Which TWO of the following are recognized categories of threat intelligence sources?
Medium6You are using MISP to ingest a feed that provides indicators in CSV format. You need to map the 'src_ip' column to the appropriate MISP attribute type. Which mapping is most accurate for ensuring effective correlation?
Hard7Which THREE of the following are considered challenges when ingesting threat intelligence feeds?
Hard8In the context of STIX 2.1, what is the purpose of the 'relationship' object?
Hard9Which TWO of the following are valid ways to improve the reliability of threat intelligence data?
Medium10Which TWO of the following are common methods used to normalize threat data from disparate sources?
Medium11Which protocol is most commonly used for the automated transport of machine-readable threat intelligence, specifically designed to support the STIX format?
Medium12You are integrating a dark web monitoring feed into your TIP. The data arrives as unstructured text. What is the most effective first step in the data processing pipeline?
Hard13Which TWO of the following are common actions performed during the 'processing' phase of the threat intelligence lifecycle?
Medium14You are configuring a TAXII client to pull STIX 2.1 data from a commercial threat intelligence platform. During testing, the client reports a 406 Not Acceptable error. What is the most likely cause?
Medium15You are setting up a STIX-to-SIEM pipeline. The SIEM requires data in CSV format. What is the critical step in your data processing architecture?
Hard16Which of the following is an example of 'structured' threat intelligence data?
Easy17When collecting data from open-source intelligence (OSINT) sources, what is the primary risk associated with automated scraping without rate-limit awareness?
Easy18Which THREE of the following are key components of a STIX 2.1 'Indicator' object?
Hard19Which of the following is a 'pull-based' method of threat intelligence data collection?
Easy20You are ingesting threat data into a TIP and notice that indicators lack 'TLP' (Traffic Light Protocol) markings. What is the standard industry procedure?
Medium21When deduplicating threat intelligence data, which unique identifier is most effective for comparing two different 'malware' objects?
Medium22When normalizing threat data using the STIX 2.1 standard, which field must be populated to define the 'type' of the observable for a file object?
Medium23Which THREE of the following are critical steps when troubleshooting a failed TAXII 2.1 server connection?
Hard24A security analyst is validating a threat feed that uses JSON. Which tool is most appropriate for verifying that the JSON structure conforms to a specific schema?
EasyOther domains
All 312-85 exam domains
Frequently asked questions
- What does the Data Collection And Processing domain cover on the 312-85 exam?
- Data Collection And Processing questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 24 Data Collection And Processing questions in the 312-85 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Data Collection And Processing questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.