88 practice questions for EC-Council Certified Threat Intelligence Analyst v2 (CTIA), exam 312-85, with full explanations.
Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.
- 88 questions mapped to the CTIA v2 exam blueprint
- Answers and explanations for every question, including the wrong options
- A questions-only PDF for timed practice runs
- Instant delivery by email the moment you check out
- Free monthly updates for as long as the exam is live
- Pass or your money back
A 312-85 attempt costs US$450. This pack is US$39, paid once.
Try 10 questions free before you buy.
Last updated September 2026 · 88 questions
What makes the CTIA hard
CTIA is a short exam, 50 questions in two hours, which means every question carries two percent of the score and there is no room to write off a domain.
The v2 version follows the intelligence lifecycle from requirements through collection, processing, analysis, dissemination and feedback, and the questions are scenario driven: a SOC receives a report, a CISO wants a risk summary, a team has to choose between feeds, and the task is to pick the analyst action, framework or source that fits.
Data Collection and Processing is the heaviest domain at 24%: OSINT, HUMINT, SIGINT and technical sources, threat feeds, dark web and cloud collection, and structuring data with STIX and TAXII. The remaining topics cover threat intelligence fundamentals, cyber threats and attack frameworks including the kill chain and MITRE ATT&CK, requirements and planning, data analysis, reporting and dissemination, threat hunting, and threat intelligence applied to SOC operations and incident response. EC-Council sets the passing score per exam form between 60% and 85%.
About the exam
312-85 (Certified Threat Intelligence Analyst v2) earns the EC-Council CTIA certification. It covers threat intelligence fundamentals, cyber threats and attack frameworks, intelligence requirements and planning, data collection and processing, data analysis, reporting and dissemination, threat hunting and detection, and threat intelligence in SOC, incident response and risk management. There are no prerequisites with official training; self-study candidates need two years of information security experience and an eligibility application.
Exam topics
- Introduction to threat intelligence
- Cyber threats and attack frameworks
- Requirements, planning, direction and review
- Data collection and processing: 24%
- Data analysis
- Intelligence reporting and dissemination
- Threat hunting and detection
- Threat intelligence in SOC operations, incident response and risk management
50 multiple choice questions, 120 minutes, passing score 60% to 85% depending on the exam form, US$450 per attempt, ECC Exam Center, Pearson VUE or remote proctoring, certification valid for three years with EC-Council continuing education.






Reviews
There are no reviews yet.