CTIA 312-85 certified threat intelligence analyst exam banner showing the syllabus arranged as the intelligence cycle

Certified Threat Intelligence Analyst: The Syllabus Is a Cycle

Read the eight CTIA topic areas in the order EC-Council lists them and something becomes obvious. Areas three, four, five and six are requirements, then collection, then analysis, then dissemination.

That is the intelligence cycle, written out as a syllabus. The Certified Threat Intelligence Analyst exam, code 312-85, is 50 multiple choice questions in two hours at a 70 percent pass mark, and EC-Council attaches no weighting to any of its eight areas. With no weights to triage by, the sequence is the only ordering signal a candidate gets, and it happens to be a good one: the middle four areas run the cycle from end to end, the first two supply the vocabulary and the frameworks, and the last two ask what the intelligence is actually for.

Why Does the CTIA Syllabus Have No Weightings?

Because the syllabus is a process rather than a set of independent subjects. EC-Council publishes eight areas for 312-85 with no percentage attached to any of them, and the middle four are the intelligence cycle in sequence. You cannot weight a cycle without implying that one of its stages matters less.

The four middle CTIA syllabus areas as the intelligence cycle: planning, collection, analysis and reporting, looping back to the start

This is genuinely unusual. Most security certifications publish weightings precisely so a candidate can allocate study time, and the absence of them here changes how preparation has to work. There is no domain you can decide to under-prepare, and there is no domain you can decide is worth half your evenings.

AreaWhat it isSub-topics listed
1. Introduction to Threat IntelligenceVocabulary and lifecycle6
2. Cyber Threats and Attack FrameworksThe models the rest of the exam uses5
3. Requirements, Planning, Direction and ReviewCycle stage one7
4. Data Collection and ProcessingCycle stage two7
5. Data AnalysisCycle stage three8
6. Intelligence Reporting and DisseminationCycle stage four9
7. Threat Hunting and DetectionApplied output2
8. Threat Intelligence in SOC Operations, Incident Response and Risk ManagementWhere it lands in the business3

The sub-topic counts are the closest thing to a weighting the syllabus offers, and they are worth reading. Dissemination lists nine sub-topics, analysis eight, and requirements and collection seven each. Threat hunting lists two. That distribution says the exam is more interested in the discipline of producing and sharing intelligence than in the glamorous end of chasing adversaries.

Testing that reading before you rely on it is straightforward: work a set of CTIA sample questions and see which stage of the cycle your wrong answers cluster in. On an unweighted syllabus that is better evidence than any study plan.

What Are the CTIA Exam Facts?

312-85 is 50 multiple choice questions in 120 minutes with a 70 percent pass mark, listed at 250 US dollars and delivered through EC-Council’s own exam portal. EC-Council confirms the question count, the duration and the pass mark on its certification page, and pairs the exam with a 24 hour course delivered over three days.

FieldValue
Exam nameCertified Threat Intelligence Analyst
Exam code312-85
Questions50, multiple choice
Duration120 minutes
Passing score70%
Price$250 USD
DeliveryEC-Council exam portal
Associated training24 hours, delivered over three days
Published areas8, unweighted

Seventy percent of 50 questions is 35 correct, so 15 wrong is the entire margin. Two hours for 50 items is 144 seconds each, which is generous, and the generosity is deliberate: several sub-topics ask you to reason about a process rather than recall a definition, and those questions take longer to read than to answer.

What EC-Council does not publish

The price is the one figure the vendor leaves out. EC-Council states on its CTIA certification page that the cost depends on the delivery mode you choose, in person, self-paced or the live online format, and refers candidates to its own site rather than naming a number. The 250 dollar figure comes from the exam listing rather than from EC-Council, so treat it as the exam-only price and budget separately for training if you take the official route.

Which Attack Frameworks Does 312-85 Name?

Three by name, in a single syllabus area: the Cyber Kill Chain, MITRE ATT&CK and the Diamond Model. Area two pairs them with advanced persistent threats and indicators of compromise, which is a compact way of saying that a threat intelligence analyst has to describe an intrusion in someone else’s vocabulary as well as their own.

The three attack models named in CTIA syllabus area two: the Kill Chain as stages, ATT and CK as a matrix of techniques, and the Diamond Model

Naming three frameworks rather than one is the point. Each describes an intrusion at a different level: the kill chain as a sequence of stages, ATT&CK as a catalogue of observed techniques, and the Diamond Model as a set of relationships between adversary, capability, infrastructure and victim. Questions in this area tend to test whether you know which one answers which kind of question.

Read the originals rather than a comparison table. The Cyber Kill Chain is published by the organisation that developed it, and its seven stages are short enough to learn properly in an evening. The technique catalogue is much larger, and the useful preparation there is navigating it rather than memorising it.

Indicators of compromise sit in the same area for a structural reason. They are the artefacts that a framework organises, so knowing the frameworks without knowing what an indicator actually looks like leaves you with a filing system and nothing to file.

What Does the Requirements and Planning Area Ask For?

Seven sub-topics, and most of them are organisational rather than technical: understanding the current threat landscape, requirements analysis, planning a threat intelligence programme, establishing management support, building a team, sharing intelligence, and reviewing the programme.

“Establish management support” is the one that surprises technical candidates, and it is a genuine examinable topic rather than filler. A threat intelligence programme that nobody senior has agreed to fund produces reports nobody reads, and EC-Council has decided that recognising this is part of the analyst’s competence.

The area is stage one of the cycle, and the cycle’s own logic explains why review is bundled in with planning. Requirements set what you will collect; review asks whether what you collected answered them. Treating those as one activity rather than as bookends is a defensible design choice and it is how the exam frames it.

Requirements analysis is the sub-topic worth the most attention. Everything downstream is wasted effort if the question was wrong, and questions in this area often present a poorly formed requirement and ask what is wrong with it.

How Much Collection Detail Does CTIA Expect?

Seven sub-topics covering data collection, collection management, feeds and sources, acquisition, bulk collection, processing and exploitation, and collection and enrichment in cloud environments. It is the area where the syllabus is most explicitly operational.

Collection management is separated from collection for a reason. Deciding what to gather, tracking whether the sources are still producing, and retiring the ones that are not is a management discipline distinct from the act of gathering, and it is where most programmes quietly degrade.

The cloud sub-topics are the newer material

Two areas name cloud environments explicitly: threat intelligence in the cloud in area one, and threat data collection and enrichment in cloud environments here. Both are additions that reflect where telemetry now lives, and they are the sub-topics least likely to be covered by older study material. Anyone preparing from a book published a few years ago should check those two specifically.

Bulk data collection is worth flagging as a distinct topic too. It carries different considerations from targeted collection, in volume, in storage cost and in the legal position of holding data you have not yet examined, and it is listed on its own rather than folded into general collection.

What Counts as Analysis on This Exam?

Eight sub-topics, and they draw a line between data analysis and threat analysis. The syllabus lists data analysis and data analysis techniques, then threat analysis and the threat analysis process, then fine-tuning that process, evaluating the intelligence produced, building runbooks and a knowledge base, and the tools involved.

The distinction matters and questions exploit it. Data analysis is what you do to a dataset. Threat analysis is what you do to a hypothesis about an adversary, and it uses the output of the first as evidence rather than as an answer. Candidates who treat the two as synonyms lose marks on questions that are testing exactly that separation.

“Fine-tuning threat analysis” is EC-Council’s phrase for filtering out the noise that a broad collection programme inevitably brings in. It is the counterpart to bulk collection in the previous area, and reading the two together makes both make more sense than reading either alone.

Creating runbooks and a knowledge base is the sub-topic that turns analysis into something an organisation keeps. An analyst who reaches the right conclusion and writes it nowhere has produced no intelligence, which is the same argument the next area makes at greater length. Our earlier 312-85 exam preparation page covers the study material available for these areas.

Why Is Dissemination the Largest Area by Sub-Topic Count?

Nine sub-topics, more than any other area: reports, dissemination, sharing relationships, sharing intelligence, delivery mechanisms, sharing platforms, the acts and regulations that govern sharing, integration, and sharing and collaboration using Python scripting. Intelligence that stays with the analyst is not intelligence.

Four of those nine are about sharing with people outside your own organisation, which tells you how central that is to the discipline. The mechanics are standardised rather than improvised: the Traffic Light Protocol is the convention that governs who a recipient may pass something on to, and understanding it is a prerequisite for participating in any sharing relationship at all.

Regulations are a named sub-topic, not background

“Intelligence sharing acts and regulations” appears explicitly in the list. Sharing indicators across organisations touches liability, privacy and in some jurisdictions specific enabling legislation, and national programmes exist precisely to make it safe. A national cyber agency’s own information sharing programme is the clearest illustration of how that operates in practice.

The Python sub-topic is the only place in the whole syllabus where code appears, and it is scoped narrowly to sharing and collaboration rather than to analysis. You are not expected to be a developer. You are expected to understand that automated sharing happens through scripted integrations and to recognise what one looks like.

Where Do Threat Hunting and SOC Operations Fit?

At the end, and smaller than most candidates expect. Threat hunting and detection lists just two sub-topics, hunting concepts and hunting automation. The final area lists three, covering how threat intelligence feeds SOC operations, risk management and incident response.

Five sub-topics between them, against 31 across the first six areas. If you came to this credential because you want to hunt, that ratio is the most important thing on this page: CTIA is a producer’s certification, not a hunter’s one, and hunting appears as one of the things the product is used for.

The final area is the business-value argument made examinable. Intelligence that improves SOC triage, sharpens a risk register or shortens an incident response is intelligence with a consumer; intelligence with no named consumer is a report. Framing each of the three consumers separately is EC-Council’s way of insisting that an analyst knows who they are writing for. Readers weighing the leadership route instead should look at the CCISO credential, which approaches the same question from the governance end.

How Should You Prepare for the 312-85 Exam?

Follow the cycle rather than the list. With no weightings published, the sequence the syllabus is written in is the best available study order, and it has the advantage that each stage supplies the input for the next. Six steps, and the first is not optional.

  1. Learn the lifecycle and its vocabulary before anything else, because the four middle areas are its four stages and none of them makes sense described out of order.
  2. Learn the three named frameworks at the level of what each is for, since the kill chain, the technique catalogue and the Diamond Model each answer a different question about the same intrusion.
  3. Practise turning a vague business concern into a stated intelligence requirement, because requirements analysis governs everything downstream and questions often present a badly formed requirement to be corrected.
  4. Separate collection from collection management in your own notes, since the syllabus separates them and the second is where real programmes degrade.
  5. Fix the distinction between data analysis and threat analysis firmly, because several sub-topics exist only to test that you do not treat them as the same activity.
  6. Give dissemination the most attention of any single area, as it carries nine sub-topics including sharing protocols, the regulations around them and scripted integration.

Then check the two cloud sub-topics deliberately, one in area one and one in area four, because they are the newest material in the syllabus and the least likely to appear in older preparation resources.

Time is not the constraint on this paper. Two hours for 50 questions leaves room to read each situation properly, so the discipline to build is accuracy on process questions rather than speed. Fifteen wrong is the allowance, and on an unweighted syllabus the wrong answers can come from anywhere.

Frequently Asked Questions

How many questions are on the CTIA exam?

50 multiple choice questions in 120 minutes, which is about 144 seconds each. EC-Council confirms the count and the duration on its own certification page.

What is the passing score for 312-85?

70 percent, which EC-Council states explicitly. On a 50 question paper that is 35 correct answers, leaving 15 wrong as the entire margin.

How much does the CTIA exam cost?

The exam is listed at 250 US dollars. EC-Council does not publish a single price for the certification because the total depends on whether you take the training in person, self-paced or in the live online format.

Does the CTIA syllabus have weightings?

No. EC-Council publishes eight topic areas with no percentage attached to any of them, which means no area can be safely under-prepared. The sub-topic counts are the closest thing to a weighting available.

Which frameworks does CTIA cover?

The Cyber Kill Chain, MITRE ATT&CK and the Diamond Model, all named in the same syllabus area alongside advanced persistent threats and indicators of compromise.

Is CTIA a threat hunting certification?

Not primarily. Threat hunting and detection is one of eight areas and lists only two sub-topics against 31 across the first six. The exam is weighted toward producing and sharing intelligence rather than hunting with it.

Does the CTIA exam require programming?

Only in one narrow sub-topic. Python appears once, under sharing and collaboration, and the expectation is that you understand how automated sharing is scripted rather than that you can write it yourself.

How long is the CTIA training course?

24 hours, delivered as a three day session with courseware and lab access. Training is offered in person, self-paced online and in a live online week format.

What can a threat intelligence analyst earn?

EC-Council publishes an average of 77,812 US dollars and a top figure of 90,605 for the role, attributed to Salary.com and current as of 1 June 2026. Those are the vendor’s published figures for the United States rather than an independent measurement.

Does CTIA cover cloud environments?

Yes, in two places: threat intelligence in the cloud in the introductory area, and threat data collection and enrichment in cloud environments in the collection area. Both are among the newest sub-topics in the syllabus.

Conclusion

The most useful thing to notice about 312-85 is structural. There are no weightings, and the eight areas are not eight subjects: four of them are the intelligence cycle in order, two set it up, and two describe what it is for.

Study it that way. Learn the lifecycle and the three named frameworks first, then work through requirements, collection, analysis and dissemination in sequence so each stage arrives with its input already understood. Give dissemination the most time, because it carries nine sub-topics including the sharing protocols and the regulations around them, and check the two cloud sub-topics separately because they are the newest material on the paper. Fifteen wrong out of 50 is a workable margin on an exam that gives you 144 seconds a question, provided the wrong ones are not all in the same stage of a cycle you skipped.

Rating: 0 / 5 (0 votes)