Free 312-85 sample questions
Real questions from the Certified Threat Intelligence Analyst (CTIA) practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A threat analyst is using the Diamond Model of Intrusion Analysis to map out an attack campaign. The analyst has identified the victim (a healthcare provider), the adversary's infrastructure (a specific VPS provider), and the capability (a known PowerShell-based malware). The analyst now needs to pivot their investigation to uncover other related campaigns. Which meta-feature of the Diamond Model would be MOST useful for this purpose?
A CTI team is automating the ingestion of threat indicators from various OSINT feeds using a Python script. They need to interact with the MISP API to add new attributes to existing events. The script has already authenticated and retrieved a specific event object. Which PyMISP function should the analyst use to add a new domain indicator to this event?
During an incident response, an analyst receives a sensitive piece of intelligence from a trusted partner in an ISAC. The intelligence contains indicators of compromise for an active campaign but also includes details about the partner's internal detection capabilities. The analyst needs to share the IoCs with their internal SOC team for immediate action but must not reveal the source's capabilities. What is this process of modifying the intelligence before dissemination called?
A threat intelligence team is investigating a series of attacks against their organization. They have collected data suggesting two possible culprits: APT-A, a known state-sponsored group, and FIN-B, a financially motivated cybercrime gang. The team lead decides to use the Analysis of Competing Hypotheses (ACH) to rigorously evaluate the evidence. Which of the following actions are critical steps in the ACH process that the team must perform? (Select THREE)
**Case Study** A multinational logistics company, ShipFast, has recently experienced a series of targeted attacks. Their CTI team, led by an experienced analyst named Maria, is tasked with building a comprehensive threat profile of the adversary. Initial intelligence suggests the attacker is a sophisticated group focused on supply chain disruption. The company uses a hybrid cloud environment, with critical shipping and tracking data stored in AWS S3 buckets and on-premises databases. Maria's team has collected various pieces of data: malware samples from compromised endpoints, network logs showing connections to unusual IP addresses, and OSINT from social media mentioning disruptions to ShipFast's competitors. The CISO needs a strategic report on the threat actor's identity and long-term intentions, while the SOC needs tactical intelligence to improve detections immediately. The team has access to a MISP instance, a SIEM, and standard malware analysis tools. To meet the CISO's needs, Maria's team must produce a strategic intelligence product. Which element is MOST crucial to include in this report for the CISO and executive board?
A threat hunter develops a hypothesis: 'An adversary is using WMI for lateral movement between workstations, evading our EDR's standard detections.' To test this, the hunter needs to search for specific event logs across the enterprise. Which Windows Event ID would be the MOST valuable to query for evidence of remote WMI command execution?
True or False: In the context of the Traffic Light Protocol (TLP), information designated as TLP:AMBER can be shared outside the recipient's organization without any restrictions.
A CTI analyst needs to collect information about the infrastructure associated with a suspected malicious domain. The goal is to find subdomains, historical IP addresses, and related SSL certificate information without directly interacting with the target domain. Which OSINT tool is specifically designed for this type of passive DNS and infrastructure analysis?
A CTI team is briefing the organization's risk management committee. The intelligence indicates a high likelihood of a specific APT group targeting their industry within the next quarter. How does this threat intelligence directly support the risk management process?
10 more free samples are waiting
Create a free account to unlock the whole 312-85 sample bank, or get full access to all 212 practice questions in the simulator.