Courseiva

312-85 · domain

Introduction TO Threat Intelligence

Practise Certified Threat Intelligence Analyst (312-85) Introduction TO Threat Intelligence practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

22 questions5 easy11 medium6 hard

Focused practice

Practice Introduction TO Threat Intelligence questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Introduction TO Threat Intelligence

Introduction TO Threat Intelligence questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Introduction TO Threat Intelligence exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Introduction TO Threat Intelligence questions (22)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO of the following are considered 'Technical' threat intelligence sources? (Choose two)

Medium
2

You are drafting a threat report for the C-suite. Which of the following is most appropriate for this audience?

Medium
3

Which TWO challenges are associated with Cloud Threat Intelligence? (Choose two)

Medium
4

When evaluating the quality of a threat intelligence source, what does the 'Timeliness' attribute specifically measure?

Medium
5

Which of the following is an example of an 'Indicator of Compromise' (IOC)?

Easy
6

In MISP, you are ingesting a CSV file of indicators. You notice that the 'Attribute' field is mapping correctly, but the 'Category' field is defaulting to 'Network activity'. What is the most efficient way to ensure the 'Category' field is parsed correctly for future imports?

Hard
7

You are configuring a TAXII client to pull indicators from an external threat feed. The client returns a 403 Forbidden error despite valid credentials. Which setting should you verify in the TAXII server configuration?

Medium
8

Your organization uses the Cyber Kill Chain. You have identified that an adversary has successfully established persistent communication with an external host. Which phase is currently active?

Medium
9

You are using the STIX 2.1 standard to document an observation. You need to link a 'Malware' object to a 'Vulnerability' object. Which Relationship object type should you use?

Hard
10

Which THREE actions are typically performed during the 'Processing' phase of the threat intelligence lifecycle? (Choose three)

Hard
11

Which TWO of the following are benefits of using a Threat Intelligence Platform (TIP)? (Choose two)

Medium
12

You are assessing a threat actor's 'Capability'. Which of the following would be considered a CTI Capability indicator?

Medium
13

Which component of the threat intelligence lifecycle involves the conversion of raw data into a format suitable for analysis?

Easy
14

Which TWO of the following are primary components of the 'Adversary' node in the Diamond Model? (Choose two)

Medium
15

You are managing threat intelligence in a cloud-native environment. You need to identify indicators related to unauthorized API key usage in AWS. Which AWS service provides the most relevant CTI data for this investigation?

Hard
16

During the 'Direction' phase of the threat intelligence lifecycle, your stakeholder requests a focus on 'Supply Chain threats'. How should you refine this requirement?

Medium
17

In the threat intelligence lifecycle, what is the 'Dissemination' phase primarily concerned with?

Easy
18

You are reviewing the Diamond Model of Intrusion Analysis for a recent incident. The 'Victim' node is populated with the targeted organization's identity. Which element should be populated in the 'Infrastructure' node?

Easy
19

You are using the MITRE ATT&CK framework to map an adversary's actions. The adversary uses 'PowerShell' to execute commands on the victim. Which Tactic does this fall under?

Hard
20

Which THREE factors should be considered when evaluating the reliability of a threat intelligence vendor? (Choose three)

Hard
21

You have received a raw feed of IP addresses. Before putting these into your firewall, you perform 'vetting'. What is the primary purpose of this vetting step?

Easy
22

You are integrating a new Threat Intelligence Platform (TIP) into your SIEM. The TIP supports the OpenIOC format. What is the primary advantage of using OpenIOC over simple CSV lists?

Medium

Frequently asked questions

What does the Introduction TO Threat Intelligence domain cover on the 312-85 exam?
Introduction TO Threat Intelligence questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 22 Introduction TO Threat Intelligence questions in the 312-85 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Introduction TO Threat Intelligence questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-ctia ECCOUNCIL-CTIA introduction to threat intelligence Practice Questions