CREST CPTIA Exam Overview:
| Certification Vendor: | CREST |
| Exam Name: | CREST Practitioner Threat Intelligence Analyst |
| Exam Number: | CPTIA |
| Exam Format: | Multiple-choice questions, Scenario-based questions |
| Passing Score: | 66% |
| Real Exam Qty: | 120 |
| Exam Price: | GBP 275 / USD 360 (varies by region) |
| Exam Duration: | 120 minutes |
| Related Certifications: | CREST Registered Threat Intelligence Analyst (CRTIA) CREST Certified Threat Intelligence Manager (CCTIM) |
| Available Languages: | English |
| Certificate Validity Period: | 3 years |
| Recommended Training: | CREST Approved Training Providers |
| Exam Registration: | Official Exam Page Pearson VUE Registration |
| Sample Questions: | CREST CPTIA Sample Questions |
| Exam Way: | Computer-based, delivered at Pearson VUE test centers worldwide |
| Pre Condition: | No mandatory prerequisites; recommended: basic cybersecurity knowledge or CompTIA Security+/Network+ |
| Official Syllabus URL: | https://www.crest-approved.org/certification-careers/crest-certifications/crest-practitioner-threat-intelligence-analyst/ |
CREST CPTIA Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Key Concepts | 17% | - Terminology and definitions - Threat vectors, vulnerabilities and risks - Objectives of Threat Intelligence - Relationship between data, information and intelligence - Threat actor types and classifications - Analytic models and attack lifecycles - Intelligence cycle and frameworks |
| Data Analysis | 17% | - Hypothesis generation and testing - Analytical techniques and structured methods - Pattern recognition and trend analysis - Assumptions, facts and inferences - Cognitive biases and analytical errors - Expressing likelihood and certainty |
| Product Dissemination | 16% | - Tailoring outputs for audiences (tactical, operational, strategic) - Types of intelligence products - Traffic Light Protocol (TLP) and handling classifications - Structured vs unstructured reporting - Intelligence sharing protocols and standards |
| Direction and Review | 17% | - Terms of reference and scope - Planning and prioritization - Reviewing intelligence outputs - Identifying intelligence gaps - Defining intelligence requirements (PIRs, SIRs) |
| Legal and Ethical Considerations | 16% | - Data protection and privacy - Ethical principles and professional conduct - CREST Code of Conduct - Legal frameworks and regulations (GDPR, DPA, etc.) - Handling sensitive and classified information |
| Data Collection | 17% | - Collection planning and management - Search techniques and query construction - Types of intelligence sources (OSINT, HUMINT, TECHINT) - Operational security (OPSEC) in collection - Source reliability and evaluation |
CREST Practitioner Threat Intelligence Analyst Sample Questions:
1. Jian is a member of the security team at Trinity, Inc. He was conducting a real-time assessment of system activities in order to acquire threat intelligence feeds. Heacquired feeds from sources like honeynets, P2P monitoring. infrastructure, and application logs.
Which of the following categories of threat intelligence feed was acquired by Jian?
A) Internal intelligence feeds
B) CSV data feeds
C) External intelligence feeds
D) Proactive surveillance feeds
2. Jim works as a security analyst in a large multinational company. Recently, a group of hackers penetrated into their organizational network and used a data staging technique to collect sensitive data. They collected all sorts of sensitive data about the employees and customers, business tactics of the organization, financial information, network infrastructure information and so on.
What should Jim do to detect the data staging before the hackers exfiltrate from the network?
A) Jim should analyze malicious DNS requests, DNS payload, unspecified domains, and destination of DNS requests.
B) Jim should identify the attack at an initial stage by checking the content of the user agent field.
C) Jim should monitor network traffic for malicious file transfers, file integrity monitoring, and event logs.
D) Jim should identify the web shell running in the network by analyzing server access, error logs, suspicious strings indicating encoding, user agent strings, and so on.
3. BadGuy Bob hid files in the slack space, changed the file headers, hid suspicious files in executables, and changed the metadata for all types of files on his hacker laptop. What has he committed?
A) Legal hostility
B) Anti-forensics
C) Felony
D) Adversarial mechanics
4. Jame, a professional hacker, is trying to hack the confidential information of a target organization. He identified the vulnerabilities in the target system and created a tailored deliverable malicious payload using an exploit and a backdoor to send it to the victim.
Which of the following phases of cyber kill chain methodology is Jame executing?
A) Installation
B) Weaponization
C) Reconnaissance
D) Exploitation
5. Which of the following types of digital evidence is temporarily stored in a digital device that requires constant power supply and is deleted if the power supply is interrupted?
A) Process memory
B) Event logs
C) Slack space
D) Swap file
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: C | Question # 3 Answer: B | Question # 4 Answer: B | Question # 5 Answer: A |

We're so confident of our products that we provide no hassle product exchange.


By Osborn


