Courseiva
Back to Certified Threat Intelligence Analyst (312-85) questions

Scenario-based practice

Hard Difficulty Questions

Practise Certified Threat Intelligence Analyst (312-85) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
312-85
exam code
EC-Council
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related 312-85 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

During an investigation, you observe an attacker utilizing a custom-compiled Trojan that bypasses EDR detection. According to the Cyber Kill Chain, at which phase is this specific action of developing the custom tool occurring?

Question 2hardmultiple choice
Full question →

You are integrating a dark web monitoring feed into your TIP. The data arrives as unstructured text. What is the most effective first step in the data processing pipeline?

Question 3hardmultiple choice
Read the full VPN explanation →

You observe an adversary using a legitimate VPN tunnel to communicate with their C2 server. Under the MITRE ATT&CK framework, which technique is this?

Question 4hardmulti select
Full question →

Which THREE of the following are key components of a STIX 2.1 'Indicator' object?

Question 5hardmultiple choice
Full question →

You are analyzing an APT threat group that consistently uses 'living-off-the-land' techniques. How should you approach identifying their presence using the MITRE ATT&CK framework?

Question 6hardmulti select
Full question →

Which THREE of the following are common attributes used to characterize an 'Observed Data' object in STIX 2.1?

Question 7hardmulti select
Full question →

Which THREE MITRE ATT&CK tactics are commonly involved in an adversary's effort to maintain a presence on a compromised system?

Question 8hardmultiple choice
Full question →

You are performing threat hunting based on the Diamond Model. You identified a new Infrastructure node (IP). What is the logical next step in the Diamond Model analysis?

Question 9hardmulti select
Full question →

Which THREE data sources are typically analyzed when investigating an insider threat according to security behavior analytics?

Question 10hardmultiple choice
Full question →

During a threat modeling session, you are analyzing a system's 'Attack Surface'. You decide to apply the 'Least Privilege' principle. Which specific analysis technique are you practicing to reduce potential pathways?

Question 11hardmultiple choice
Full question →

You are troubleshooting a feed ingestion failure in an OpenCTI platform where the connector logs show '403 Forbidden' during a HTTPS pull. What is the primary troubleshooting step?

Question 12hardmultiple choice
Full question →

You are using MISP to ingest a feed that provides indicators in CSV format. You need to map the 'src_ip' column to the appropriate MISP attribute type. Which mapping is most accurate for ensuring effective correlation?

Question 13hardmultiple choice
Full question →

While processing threat intelligence, you encounter an indicator containing a 'base64' encoded payload. Which action should be performed during normalization to maintain searchability?

Question 14hardmultiple choice
Full question →

In the context of STIX 2.1, what is the purpose of the 'relationship' object?

Question 15hardmultiple choice
Full question →

An analyst is mapping internal incident data to STIX 2.1 objects. You need to link a specific threat actor to the infrastructure they recently utilized. Which object type should you use to link the 'Threat-Actor' object to the 'Infrastructure' object?

Question 16hardmultiple choice
Full question →

You are troubleshooting an issue where a SIEM cannot parse an incoming STIX 2.1 bundle. The bundle contains a 'Relationship' object linking a 'Malware' object to an 'Infrastructure' object. Which property within the 'Relationship' object must be verified to ensure the link type is recognized by the parser?

Question 17hardmulti select
Full question →

Which THREE actions are typically performed during the 'Processing' phase of the threat intelligence lifecycle? (Choose three)

Question 18hardmultiple choice
Full question →

An intelligence manager is reviewing the threat intelligence program's intelligence gap analysis. The analysis reveals that the team frequently fails to detect supply chain intrusions until late in the attack lifecycle. Which adjustments to the direction and planning phase should the manager implement?

Question 19hardmultiple choice
Full question →

You are using the MITRE ATT&CK framework to map an adversary's actions. The adversary uses 'PowerShell' to execute commands on the victim. Which Tactic does this fall under?

Question 20hardmultiple choice
Full question →

A CTI team is conducting a threat landscape analysis for a global financial institution. The analyst wants to apply the Diamond Model of Intrusion Analysis during the requirements planning phase to scope out potential adversary capabilities and infrastructure requirements. Which vertex of the Diamond Model directly captures the tools and techniques used by the adversary?

These 312-85 practice questions are part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style 312-85 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.