312-85: EC-Council Certified Threat Intelligence Analyst (CTIA)
Browse certifications
Exam Resources
Official learning paths, exam details, skills measured, and community resources to supplement your study.
About the CTIA (312-85) Exam
Turn raw threat data into decision-ready intelligence — the cyber threat intelligence lifecycle, frameworks, collection, analysis, dissemination, and hunting.
The EC-Council Certified Threat Intelligence Analyst (CTIA v2, exam 312-85) validates the skills a working cyber threat intelligence analyst needs to plan, collect, analyze, and disseminate intelligence that actually drives defense. It covers eight domains: Introduction to Threat Intelligence (intelligence-led security, the four CTI types and their consumers, the intelligence lifecycle, and threat intelligence platforms), Cyber Threats and Attack Frameworks (threat actors, APTs, the Lockheed Martin Cyber Kill Chain, MITRE ATT&CK and the Diamond Model, and indicators of compromise with the Pyramid of Pain), Requirements, Planning, Direction, and Review (priority intelligence requirements, program planning, and building a CTI team), Data Collection and Processing (collection management, OSINT and feeds, bulk collection, processing and enrichment, and cloud collection), Data Analysis (structured analytic techniques, the threat-analysis process, reducing bias, source-reliability scoring, and analysis tools), Dissemination and Reporting of Intelligence (report types, the Traffic Light Protocol, sharing communities, and STIX/TAXII/MISP), Threat Hunting and Detection (hypothesis-driven hunting mapped to ATT&CK, and hunt automation), and Threat Intelligence in SOC Operations, Incident Response, and Risk Management. Every practice question is an original analyst scenario with detailed explanations, why-wrong analysis, and exam tips.
Who Should Take This Exam?
The CTIA is an intermediate-level certification for threat intelligence analysts, SOC analysts, security analysts, incident responders, and blue-team members who want to build or formalize a cyber threat intelligence capability. EC-Council recommends either official CTIA training or an eligibility application backed by two or more years of information-security experience. Hands-on familiarity with SOC operations, MITRE ATT&CK, and threat-intelligence tooling helps.
Typical study time: 6-10 weeks of focused study
Exam Quick Facts
| Detail | Value |
|---|---|
| Exam Code | 312-85 |
| Title | EC-Council Certified Threat Intelligence Analyst (CTIA v2) |
| Duration | 120 minutes |
| Questions | 50 |
| Pass Score | 70% (form-dependent) |
| Cost | $450 USD |
| Provider | ECC Exam Portal (EC-Council) |
| Validity | 3 years (ECE required) |
| Question Types | Multiple choice |
| Official Page | View on EC-Council → |
Exam Domains & Weights
The CTIA exam covers 8 domains. Focus your study time based on the weights below — higher-weighted domains have more exam questions.
| Domain | Weight | Practice Qs |
|---|---|---|
| Introduction to Threat Intelligence | 12% | 27 |
| Cyber Threats and Attack Frameworks | 8% | 24 |
| Requirements, Planning, Direction, and Review | 14% | 31 |
| Data Collection and Processing | 24% | 53 |
| Data Analysis | 16% | 36 |
| Dissemination and Reporting of Intelligence | 14% | 31 |
| Threat Hunting and Detection | 6% | 24 |
| Threat Intelligence in SOC Operations, Incident Response, and Risk Management | 6% | 24 |
| Total | 100% | 250 |
💡 Study tip: Data Collection and Processing carries the most weight (24%) — start there, since collection management, feeds and sources, processing, and enrichment span the largest share of exam questions. Data Analysis (16%) is next; make sure you can apply structured analytic techniques and score source reliability with the Admiralty scale. The two lightest domains — Threat Hunting and Detection and Threat Intelligence in SOC/IR/Risk (6% each) — still show up, so don’t skip them.
Practice Exam — 250 Questions
Prepare for the CTIA exam with our 250-question practice exam covering all 8 exam domains. Every question includes detailed explanations, why-wrong analysis, and exam tips, and maps to the official CTIA v2 exam blueprint.
What you get:
- ✅ Exam simulation mode with timer
- ✅ Spaced repetition for weak areas
- ✅ Detailed explanations for every question
- ✅ Progress tracking across domains
- ✅ 20 free questions — no account needed
EC-Council Certification Path
CTIA sits in EC-Council’s blue-team / defensive track alongside CND (network defense) and CHFI (forensics), and complements the offensive CEH. There’s no strict hierarchy — pick the credential that matches your role. CTIA is the natural choice if your work centers on threat intelligence, SOC analysis, or building a CTI program.
Related EC-Council Certifications
If you’re studying for the CTIA exam, you might also be interested in these EC-Council certifications:
- CEH-V13: EC-Council Certified Ethical Hacker (CEH) v13 — 250 practice questions
- CHFI-V11: EC-Council Certified Hacking Forensic Investigator v11 — 200 practice questions
- CND-V3: EC-Council Certified Network Defender v3 — 200 practice questions
Study Tips
- Start with Data Collection and Processing — at 24% it is the heaviest domain; master collection management, feeds and sources, processing, enrichment, and cloud collection first
- Learn the frameworks cold — the Cyber Kill Chain, MITRE ATT&CK (tactics vs techniques), the Diamond Model, and the Pyramid of Pain recur across domains
- Know your standards — be able to contrast STIX (the representation) with TAXII (the transport), and get the Traffic Light Protocol (TLP 2.0) and Admiralty source-reliability scale right
- Use our practice exam — try the 20 free questions first to gauge your readiness
- Simulate exam conditions — use the timed exam mode to practice under pressure