312-85 · domain
Requirements Planning Direction And Review
Practise Certified Threat Intelligence Analyst (312-85) Requirements Planning Direction And Review practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Requirements Planning Direction And Review questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Requirements Planning Direction And Review
Requirements Planning Direction And Review questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Requirements Planning Direction And Review exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Requirements Planning Direction And Review questions (24)
Click any question to see the full explanation, or start a practice session above.
An intelligence analyst is drafting the Request for Information (RFI) workflow during the direction phase. An operational team submits an RFI regarding a newly observed malware strain. What is the correct next step in the RFI management lifecycle?
Medium2A CTI program is conducting a formal review of its intelligence requirements to ensure alignment with changing business goals. Which phase of the intelligence cycle directly feeds into the direction and planning phase during this review?
Medium3An organization is updating its threat landscape analysis methodology to better account for sector-specific threats. Which stakeholder group should the CTI team primarily consult to gather accurate sector-specific threat requirements?
Easy4An organization is structuring a new Threat Intelligence (TI) team and needs to ensure that strategic intelligence reaches executive leadership effectively. Which team role is primarily responsible for translating high-level threat trends into business risk assessments for board members?
Easy5When establishing a Threat Intelligence program, a manager must outline the core functions of the TI team. Which TWO of the following responsibilities typically fall under a dedicated CTI team's scope? (Choose TWO)
Easy6During the requirements planning phase, a CTI analyst categorizes intelligence needs based on consumer levels. Which THREE types of intelligence consumers must be addressed in a comprehensive intelligence plan? (Choose THREE)
Medium7During the Requirements Planning phase of the intelligence cycle, a CTI analyst uses the Priority Intelligence Requirements (PIR) framework. What is the primary purpose of defining PIRs at this stage?
Medium8When planning a Threat Intelligence program budget, an organization must account for various resource categories. Which THREE resource categories should be included in the CTI program budget plan? (Choose THREE)
Medium9An organization is establishing metrics for its Threat Intelligence program review. The CTI director wants to measure 'Collection Efficiency.' Which formula or evaluation method best represents this metric?
Medium10An intelligence manager is reviewing the threat intelligence program's intelligence gap analysis. The analysis reveals that the team frequently fails to detect supply chain intrusions until late in the attack lifecycle. Which adjustments to the direction and planning phase should the manager implement?
Hard11An intelligence manager is evaluating sources for a threat intelligence program during the planning phase. Which TWO criteria are critical when vetting a new external threat intelligence vendor or feed? (Choose TWO)
Hard12An organization is conducting a review of its threat intelligence program to assess alignment with intelligence-driven defense models. Which TWO frameworks are widely used to structure threat intelligence planning, collection, and defense operations? (Choose TWO)
Hard13An intelligence analyst is tasked with tailoring intelligence requirements for a merger and acquisition (M&A) scenario. Which methodology should be applied during the direction phase to identify threat actors specifically interested in compromising corporate transactions?
Hard14When building a Threat Intelligence team, the Chief Information Security Officer (CISO) must decide between centralizing the TI function or distributing analysts across various business units. What is a primary advantage of a centralized TI team structure?
Easy15During the threat landscape analysis and requirements gathering process, an organization must identify its critical assets and crown jewels. Which THREE categories represent typical critical assets that should drive intelligence requirements? (Choose THREE)
Medium16A newly formed CTI team is conducting stakeholder interviews to establish intelligence requirements. The Chief Risk Officer (CRO) expresses concern over ransomware supply chain disruptions. How should the intelligence analyst translate this concern into a formal intelligence requirement?
Medium17During the planning phase of building a CTI team, the program manager needs to define the scope of intelligence operations. Which category of intelligence focuses specifically on technical indicators such as file hashes, IP addresses, and domain names?
Easy18During program planning for a CTI team, the program manager must define stakeholder engagement protocols. Which THREE stakeholder groups should be actively engaged during the requirements planning and review phases? (Choose THREE)
Medium19A CTI program manager is defining Key Performance Indicators (KPIs) to measure the effectiveness of the intelligence program during the review phase. Which metric best measures the quality and relevance of the intelligence produced?
Medium20An intelligence analyst is performing a threat landscape analysis using the Cyber Kill Chain framework. During the planning phase, the analyst wants to map collection requirements to disrupt adversaries during the 'Weaponization' phase. What specific intelligence should the analyst plan to collect?
Hard21An intelligence analyst is drafting the collection management framework during the planning phase. Which TWO activities are key components of collection management? (Choose TWO)
Easy22During program planning for a threat intelligence capability, the security team maps their intelligence processes to the NIST Cybersecurity Framework (CSF). Which CSF function is most directly aligned with establishing Threat Intelligence requirements, gathering sources, and reviewing intelligence collection efficacy?
Hard23A CTI team is conducting a threat landscape analysis for a global financial institution. The analyst wants to apply the Diamond Model of Intrusion Analysis during the requirements planning phase to scope out potential adversary capabilities and infrastructure requirements. Which vertex of the Diamond Model directly captures the tools and techniques used by the adversary?
Hard24During the CTI team building process, the manager needs to hire personnel with analytical mindsets who can avoid cognitive biases. Which cognitive bias involves favoring information that confirms pre-existing beliefs while discarding contradictory evidence?
EasyOther domains
All 312-85 exam domains
Frequently asked questions
- What does the Requirements Planning Direction And Review domain cover on the 312-85 exam?
- Requirements Planning Direction And Review questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 24 Requirements Planning Direction And Review questions in the 312-85 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Requirements Planning Direction And Review questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.