Sample questions
Certified Threat Intelligence Analyst (312-85) practice questions
You are mapping an adversary behavior to the MITRE ATT&CK framework. The attacker uses PowerShell to execute a Base64 encoded payload that downloads a secondary script. Under which…
In the context of data analysis for CTI, what is the primary purpose of normalizing disparate log data from multiple SIEM sources?
A security analyst is using the Diamond Model to document an incident. The analyst notes that the adversary used a specific Command and Control (C2) server IP address. In the conte…
During an investigation, you observe an attacker utilizing a custom-compiled Trojan that bypasses EDR detection. According to the Cyber Kill Chain, at which phase is this specific…
What does a high 'CVSS' score indicate in the context of vulnerability data analysis?
You are integrating a dark web monitoring feed into your TIP. The data arrives as unstructured text. What is the most effective first step in the data processing pipeline?
You observe an adversary using a legitimate VPN tunnel to communicate with their C2 server. Under the MITRE ATT&CK framework, which technique is this?
When hunting for malicious DLL side-loading, which file property is most critical to verify?
An analyst is examining logs and finds a pattern of periodic heartbeat pings to an unknown external domain. Which MITRE ATT&CK tactic does this activity suggest?
Which THREE of the following are key components of a STIX 2.1 'Indicator' object?
Which TWO of the following are necessary to include when creating a high-quality threat intelligence report for an operational team?
Intelligence Reporting And DisseminationmediumSee the answer and why each option is right or wrong →What is the primary purpose of the 'Actions on Objectives' phase in the Cyber Kill Chain?
You are analyzing an APT threat group that consistently uses 'living-off-the-land' techniques. How should you approach identifying their presence using the MITRE ATT&CK framework?
You are assessing a company's incident response capability against the Cyber Kill Chain. If an attacker has successfully completed the 'Installation' phase, which defensive control…
Which of the following is a common pitfall when performing 'Trend Analysis' on threat data?
Which THREE of the following are common attributes used to characterize an 'Observed Data' object in STIX 2.1?
A security analyst is validating a threat feed that uses JSON. Which tool is most appropriate for verifying that the JSON structure conforms to a specific schema?
Which phase of the Cyber Kill Chain is primarily mitigated by effective security awareness training for employees?
Which THREE MITRE ATT&CK tactics are commonly involved in an adversary's effort to maintain a presence on a compromised system?
You are drafting an executive threat report and need to adhere to the Traffic Light Protocol (TLP). The report contains sensitive information about an ongoing vulnerability in a ze…
Intelligence Reporting And DisseminationmediumSee the answer and why each option is right or wrong →An intelligence analyst is drafting the collection management framework during the planning phase. Which TWO activities are key components of collection management? (Choose TWO)
Requirements Planning Direction And RevieweasySee the answer and why each option is right or wrong →You are performing threat hunting based on the Diamond Model. You identified a new Infrastructure node (IP). What is the logical next step in the Diamond Model analysis?
You are ingesting threat data into a TIP and notice that indicators lack 'TLP' (Traffic Light Protocol) markings. What is the standard industry procedure?
You are drafting a threat report for the C-suite. Which of the following is most appropriate for this audience?