Courseiva
Back to Certified Threat Intelligence Analyst (312-85) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Threat Intelligence Analyst (312-85) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
312-85
exam code
EC-Council
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related 312-85 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which THREE of the following are key components of a STIX 2.1 'Indicator' object?

Question 2mediummulti select
Full question →

Which TWO of the following are necessary to include when creating a high-quality threat intelligence report for an operational team?

Question 3hardmulti select
Full question →

Which THREE of the following are common attributes used to characterize an 'Observed Data' object in STIX 2.1?

Question 4hardmulti select
Full question →

Which THREE MITRE ATT&CK tactics are commonly involved in an adversary's effort to maintain a presence on a compromised system?

Question 5easymulti select
Full question →

An intelligence analyst is drafting the collection management framework during the planning phase. Which TWO activities are key components of collection management? (Choose TWO)

Question 6mediummulti select
Full question →

Which TWO of the following are considered 'Indicator of Compromise' (IOC) types?

Question 7mediummulti select
Full question →

Which THREE factors should be considered when evaluating the reliability of threat intelligence data used in your analysis?

Question 8hardmulti select
Full question →

Which THREE data sources are typically analyzed when investigating an insider threat according to security behavior analytics?

Question 9mediummulti select
Full question →

Which TWO challenges are associated with Cloud Threat Intelligence? (Choose two)

Question 10mediummulti select
Full question →

You are auditing your TAXII server configuration for data sharing compliance. Which TWO of the following items must be explicitly defined for each collection to ensure correct data governance and access control?

Question 11hardmulti select
Full question →

Which THREE actions are typically performed during the 'Processing' phase of the threat intelligence lifecycle? (Choose three)

Question 12hardmulti select
Full question →

Which THREE of the following are valid reasons to use the STIX 'Sighting' object?

Question 13mediummulti select
Full question →

Which THREE types of information should be collected during the 'Processing' phase of the intelligence cycle to ensure data quality?

Question 14mediummulti select
Full question →

Which TWO of the following are primary components of the 'Adversary' node in the Diamond Model? (Choose two)

Question 15mediummulti select
Full question →

Which TWO of the following are benefits of using a Threat Intelligence Platform (TIP)? (Choose two)

Question 16mediummulti select
Full question →

During program planning for a CTI team, the program manager must define stakeholder engagement protocols. Which THREE stakeholder groups should be actively engaged during the requirements planning and review phases? (Choose THREE)

Question 17mediummulti select
Full question →

During the requirements planning phase, a CTI analyst categorizes intelligence needs based on consumer levels. Which THREE types of intelligence consumers must be addressed in a comprehensive intelligence plan? (Choose THREE)

Question 18mediummulti select
Full question →

When planning a Threat Intelligence program budget, an organization must account for various resource categories. Which THREE resource categories should be included in the CTI program budget plan? (Choose THREE)

Question 19mediummulti select
Full question →

Which THREE actions should a SOC team perform when a high-confidence indicator is received via a threat intelligence feed?

Question 20hardmulti select
Full question →

Which THREE of the following are primary components (vertices) of the Diamond Model of Intrusion Analysis?

These 312-85 practice questions are part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style 312-85 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.