EC-COUNCIL · 312-85

EC-Council 312-85 CTIA v2 Exam Practice Questions

88 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 88 questions in this pack

Question 1

Daniel is a professional hacker whose aim is to attack a system to steal data and money for profit. He performs hacking to obtain confidential data such as social security numbers, personally identifiable information (PII) of an employee, and credit card information. After obtaining confidential data, he further sells the information on the black market to make money.

Daniel comes under which of the following types of threat actor.

  1. Industrial spies
  2. State-sponsored hackers
  3. Insider threat
  4. Organized hackers
Show answer and explanation

Correct answer: D. Organized hackers

Daniel engages in financially motivated cybercrime by stealing sensitive data and selling it on the black market for profit. This characterizes him as an organized hacker, part of a criminal enterprise focused on monetary gain through data theft and resale. Industrial spies work for competing organizations, state-sponsored hackers serve government interests, and insider threats originate from within organizations; none of these match Daniel's profile of external criminal activity for financial profit.

Why the other options are wrong

  • A. Industrial spies conduct corporate espionage for competing businesses, not independent criminal data sales.
  • B. State-sponsored hackers work on behalf of governments for political or strategic objectives, not personal profit.
  • C. Insider threats originate from within an organization with internal access, whereas Daniel operates externally.

Question 2

An attacker instructs bots to use camouflage mechanism to hide his phishing and malware delivery locations in the rapidly changing network of compromised bots. In this particular technique, a single domain name consists of multiple IP addresses.

Which of the following technique is used by the attacker?

  1. DNS zone transfer
  2. Dynamic DNS
  3. DNS interrogation
  4. Fast-Flux DNS
Show answer and explanation

Correct answer: D. Fast-Flux DNS

Fast-Flux DNS is a technique where a single domain name is associated with multiple rapidly changing IP addresses, all pointing to compromised bot nodes. This provides camouflage by making it difficult to track and block phishing and malware delivery locations as they shift across the botnet infrastructure. DNS zone transfer involves copying entire DNS databases between servers, Dynamic DNS updates DNS records in real-time for legitimate purposes, and DNS interrogation queries DNS information, none specifically describe this botnet evasion method.

Why the other options are wrong

  • A. DNS zone transfer is an administrative process for replicating DNS databases, not a camouflage technique for botnets.
  • B. Dynamic DNS is used for legitimate purposes like updating DNS records for devices with changing IP addresses.
  • C. DNS interrogation refers to querying DNS servers for information, not a technique for hiding malware delivery infrastructure.

Question 3

Kathy wants to ensure that she shares threat intelligence containing sensitive information with the appropriate audience. Hence, she used traffic light protocol (TLP).

Which TLP color would you signify that information should be shared only within a particular community?

  1. Red
  2. White
  3. Green
  4. Amber
Show answer and explanation

Correct answer: C. Green

Under the Traffic Light Protocol, TLP:GREEN means limited disclosure restricted to the community, so the information can circulate among peer organizations and partners in a sector or sharing community but not publicly. That matches Kathy's goal of releasing sensitive intelligence to a particular community of interest. TLP:GREEN is the correct marking for community-wide sharing.

Why the other options are wrong

  • A. TLP:RED is the most restrictive marking and limits the information to the named individuals present at the exchange, with no further sharing at all.
  • B. TLP:WHITE (now TLP:CLEAR) permits unlimited public distribution, which defeats the purpose of protecting sensitive intelligence.
  • D. TLP:AMBER is narrower than GREEN because it confines the information to the recipient's own organization and, where needed, its clients, rather than releasing it to a wider community.

See all 10 free questions Get the full pack, US$39

88 practice questions for EC-Council Certified Threat Intelligence Analyst v2 (CTIA), exam 312-85, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 88 questions mapped to the CTIA v2 exam blueprint
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A 312-85 attempt costs US$450. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 88 questions

What makes the CTIA hard

CTIA is a short exam, 50 questions in two hours, which means every question carries two percent of the score and there is no room to write off a domain.

The v2 version follows the intelligence lifecycle from requirements through collection, processing, analysis, dissemination and feedback, and the questions are scenario driven: a SOC receives a report, a CISO wants a risk summary, a team has to choose between feeds, and the task is to pick the analyst action, framework or source that fits.

Data Collection and Processing is the heaviest domain at 24%: OSINT, HUMINT, SIGINT and technical sources, threat feeds, dark web and cloud collection, and structuring data with STIX and TAXII. The remaining topics cover threat intelligence fundamentals, cyber threats and attack frameworks including the kill chain and MITRE ATT&CK, requirements and planning, data analysis, reporting and dissemination, threat hunting, and threat intelligence applied to SOC operations and incident response. EC-Council sets the passing score per exam form between 60% and 85%.

About the exam

312-85 (Certified Threat Intelligence Analyst v2) earns the EC-Council CTIA certification. It covers threat intelligence fundamentals, cyber threats and attack frameworks, intelligence requirements and planning, data collection and processing, data analysis, reporting and dissemination, threat hunting and detection, and threat intelligence in SOC, incident response and risk management. There are no prerequisites with official training; self-study candidates need two years of information security experience and an eligibility application.

Exam topics

  • Introduction to threat intelligence
  • Cyber threats and attack frameworks
  • Requirements, planning, direction and review
  • Data collection and processing: 24%
  • Data analysis
  • Intelligence reporting and dissemination
  • Threat hunting and detection
  • Threat intelligence in SOC operations, incident response and risk management

50 multiple choice questions, 120 minutes, passing score 60% to 85% depending on the exam form, US$450 per attempt, ECC Exam Center, Pearson VUE or remote proctoring, certification valid for three years with EC-Council continuing education.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the EC-Council 312-85 CTIA v2 pack?

88 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.