Courseiva

312-85 · domain

Data Collection And Processing

Practise Certified Threat Intelligence Analyst (312-85) Data Collection And Processing practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

24 questions4 easy10 medium10 hard

Focused practice

Practice Data Collection And Processing questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Data Collection And Processing

Data Collection And Processing questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Data Collection And Processing exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Data Collection And Processing questions (24)

Click any question to see the full explanation, or start a practice session above.

1

Which THREE of the following are common attributes used to characterize an 'Observed Data' object in STIX 2.1?

Hard
2

You are troubleshooting a feed ingestion failure in an OpenCTI platform where the connector logs show '403 Forbidden' during a HTTPS pull. What is the primary troubleshooting step?

Hard
3

You are configuring a TAXII 2.1 feed in a SIEM. You need to ensure that the collection process only retrieves high-confidence indicators. Where is this filter typically applied?

Medium
4

While processing threat intelligence, you encounter an indicator containing a 'base64' encoded payload. Which action should be performed during normalization to maintain searchability?

Hard
5

Which TWO of the following are recognized categories of threat intelligence sources?

Medium
6

You are using MISP to ingest a feed that provides indicators in CSV format. You need to map the 'src_ip' column to the appropriate MISP attribute type. Which mapping is most accurate for ensuring effective correlation?

Hard
7

Which THREE of the following are considered challenges when ingesting threat intelligence feeds?

Hard
8

In the context of STIX 2.1, what is the purpose of the 'relationship' object?

Hard
9

Which TWO of the following are valid ways to improve the reliability of threat intelligence data?

Medium
10

Which TWO of the following are common methods used to normalize threat data from disparate sources?

Medium
11

Which protocol is most commonly used for the automated transport of machine-readable threat intelligence, specifically designed to support the STIX format?

Medium
12

You are integrating a dark web monitoring feed into your TIP. The data arrives as unstructured text. What is the most effective first step in the data processing pipeline?

Hard
13

Which TWO of the following are common actions performed during the 'processing' phase of the threat intelligence lifecycle?

Medium
14

You are configuring a TAXII client to pull STIX 2.1 data from a commercial threat intelligence platform. During testing, the client reports a 406 Not Acceptable error. What is the most likely cause?

Medium
15

You are setting up a STIX-to-SIEM pipeline. The SIEM requires data in CSV format. What is the critical step in your data processing architecture?

Hard
16

Which of the following is an example of 'structured' threat intelligence data?

Easy
17

When collecting data from open-source intelligence (OSINT) sources, what is the primary risk associated with automated scraping without rate-limit awareness?

Easy
18

Which THREE of the following are key components of a STIX 2.1 'Indicator' object?

Hard
19

Which of the following is a 'pull-based' method of threat intelligence data collection?

Easy
20

You are ingesting threat data into a TIP and notice that indicators lack 'TLP' (Traffic Light Protocol) markings. What is the standard industry procedure?

Medium
21

When deduplicating threat intelligence data, which unique identifier is most effective for comparing two different 'malware' objects?

Medium
22

When normalizing threat data using the STIX 2.1 standard, which field must be populated to define the 'type' of the observable for a file object?

Medium
23

Which THREE of the following are critical steps when troubleshooting a failed TAXII 2.1 server connection?

Hard
24

A security analyst is validating a threat feed that uses JSON. Which tool is most appropriate for verifying that the JSON structure conforms to a specific schema?

Easy

Frequently asked questions

What does the Data Collection And Processing domain cover on the 312-85 exam?
Data Collection And Processing questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 24 Data Collection And Processing questions in the 312-85 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Data Collection And Processing questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Certified Threat Intelligence Analyst (312-85) Data Collection And Processing Practice Questions