Threat Intelligence Analyst Career: Skills, Exam and Certification Path
A threat intelligence analyst collects, processes and analyses information about attackers so an organisation can anticipate and respond to cyber threats. CREST assesses this role through its Registered Threat Intelligence Analyst exam, aimed at people who already work in a team delivering threat intelligence and have at least two years of hands-on experience.
If that describes you, the CRTIA practice test on EduSum lets you check your readiness against the same syllabus areas this guide walks through, before you book a seat. You can also start with the free threat intelligence analyst sample questions to see the question style.

What does a threat intelligence analyst actually do?
On its Registered Threat Intelligence Analyst certification page and in the syllabus, CREST defines the role as responsible for the collection, processing and analysis of data, information and intelligence in order to produce threat intelligence outputs. In practice that means turning raw material, from domain registration records to social media activity and malware indicators, into a clear assessment a decision-maker can act on.
The work has two sides. Contextual analysis looks at social, cultural and geopolitical factors behind an attack, such as who benefits and why now. Technical analysis works with indicators of compromise, the IP addresses, domains, file hashes and behaviours that reveal an intrusion. A good analyst moves between both and explains the result in plain language.
People reach this role from different directions. CREST notes that analysts may come from information security, but also from private security, police, military or intelligence backgrounds. Whatever the route, the job carries legal and ethical obligations, because collecting information about people and groups is tightly regulated.
Outputs range from short alerts about a single campaign to tailored reports for senior leaders or a regulator. The syllabus expects you to choose the right format for each audience and to share machine-readable indicators with partners in a form their security tools can use.
Strategic, operational and tactical intelligence
Threat intelligence teams usually serve three kinds of reader. Strategic intelligence helps executives understand which threats matter to the business and why, so it focuses on motivation, trends and risk rather than technical detail. Operational intelligence describes specific campaigns and adversaries, helping security managers plan defences and prioritise work. Tactical intelligence is the most technical, covering indicators and attacker techniques that defenders can feed straight into detection tools. A registered analyst is expected to work across all three and to judge which level a customer actually needs.
A typical engagement from start to finish
The CREST syllabus follows the life of a real engagement, and it helps to picture one before you study the detail. It starts with direction: understanding the customer's position, agreeing what questions the intelligence must answer, setting timescales and establishing rules of engagement. Collection comes next, guided by a plan that names sources, methods and the legal basis for gathering each type of data.
Analysis then turns collected material into judgements, using structured methods and a deliberate search for bias and misinformation. Dissemination delivers the product in the format each reader needs, from a technical indicator feed to a board-level briefing. Finally, the engagement is reviewed with the customer so that successes and failures shape the next piece of work. Every long-form answer you write in the exam is easier if you can place the question somewhere in this cycle.
Which skills does CREST expect you to have?
The CREST syllabus for registered threat intelligence analysts is divided into eight knowledge groups. Each one maps to a part of real engagements, from agreeing what the customer needs to delivering the final report. The syllabus also marks every skill area as assessed in the multiple-choice paper, the long-form questions or both, which is a useful guide to how deeply you need to know it.

Key concepts
This group sets out the ideas that everything else rests on. You need to explain the business case for intelligence-led security and the range of situations where threat intelligence helps an organisation. Expect terminology covering threat intelligence, business risk and information security, and knowledge of common threat actors such as hacktivists, criminals and nation states, including their motivation and intent. The benefits of attribution, linking activity to real people, places or organisations, also appear here.
Attack methodology covers the phases of the cyber kill chain, common tactics, techniques and procedures, and familiarity with the MITRE ATT&CK framework. Analysis methodology includes the Diamond Model, analysis of competing hypotheses and intelligence preparation of the environment, plus forecasting and predictive concepts. Two skill areas, the intelligence lifecycle including F3EAD and the principles of intelligence, are assessed only through long-form answers, so be ready to discuss them in your own words.
Direction and review
Direction is where engagements succeed or fail. The syllabus expects you to analyse an intelligence customer's position, scope a project around the outcomes that matter to that organisation, plan realistic timescales and resources, and establish rules of engagement, limitations and constraints. Prioritisation methods such as MoSCoW appear, along with basic mapping of how a customer will consume and apply the intelligence you produce.
Review closes the loop. After an engagement, the analyst should assess successes and failures together with the customer. This skill is assessed through long-form questions, so practise describing a review that is honest about gaps rather than one that only celebrates results.
Data collection
Collection is the largest knowledge group. It begins with building a collection plan that is efficient, agile, robust and appropriate, and continues with understanding intelligence sources such as OSINT, HUMINT and SIGINT, including the legal frameworks that apply to collecting data from technical and human sources. Source reliability is central: you should know how to rate a source for credibility and relevance, how collection methods affect the freshness of data, and the difference between deception, disinformation and misinformation.
The technical side covers IP and domain registration records, DNS queries and responses, zone transfers, common record types, dynamic DNS providers and fast-flux DNS. You should also know how to use search engines and social networks for open source research, what metadata common document formats reveal, and how leak and dump sites have been used to share stolen data. Operational security matters too, including protecting the safety and anonymity of collectors and running alias accounts for monitoring. The group ends with bulk data collection from sources such as passive DNS and malware feeds, and with the legal and reliability issues of handling human sources.
Data analysis
Analysis turns data into answers. Contextualisation asks you to understand the political, economic, social and technological environment around data and its sources. Analysis methodologies include sorting and filtering data, standard qualitative and quantitative methods, social network analysis, behavioural profiling, threat modelling and attack trees. Machine-based techniques cover structured and unstructured data analysis and awareness of supervised and unsupervised machine learning.
Statistics appear in the multiple-choice paper: averages, standard deviation, statistical distributions, correlation, time-series analysis, graphing and charting techniques and confidence levels. The critique skill area asks you to explore all plausible hypotheses, spot fake or conflicting data, understand the difference between prediction and forecasting, and recognise the gap between secrets, which can be discovered, and mysteries, which cannot. Removing bias introduced by collection or analysis methods is part of the same skill. Consistency of analysis across engagements and sectors is assessed through long-form answers.
Product dissemination
Intelligence has no value until it reaches the right person in a usable form. The syllabus covers delivery mechanisms from simple alerts to tailored reports, and why machine-readable formats matter for efficient sharing between organisations. You should know what makes technical defensive intelligence useful, including host-based and network-based indicators, and the common formats used to distribute indicators of compromise to partners.
Intelligence sharing initiatives and their relevance to individual clients are assessed through long-form questions. Handling and classification complete the group: formal data classification and handling policies, and how to establish secure delivery using measures such as data encryption and strong authentication.
Management
Registered analysts are expected to manage work, not only perform it. Client management covers knowledge sharing, regular checkpoints, escalation paths and secure out-of-band communication channels. Project management includes leading a team of analysts, understanding the full engagement lifecycle from scoping and authorisation to non-disclosure agreements and review, and making sound decisions under pressure.
Reporting is assessed in long-form answers and asks for concise reports with clear limitations, caveats and assumptions, a coherent narrative that meets the reader's intelligence needs, and graphical ways to present complicated links. Risk management covers the extra risks of threat-led engagements and awareness of standards including ISO 31000, ISO 27001, ISO 22301 and ISO 27005. The group ends with working professionally with third parties, government departments and regulators, and a basic understanding of regulator-mandated, intelligence-led testing schemes.
Legal and ethical
The legal skill area lists UK legislation relevant to intelligence work: the Computer Misuse Act 1990, the Human Rights Act 1998, the Data Protection Act 1998, the Police and Justice Act 2006, the Official Secrets Act 1989, the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000, the Regulation of Investigatory Powers Act 2000, the Bribery Act 2010 and the Proceeds of Crime Act 2002. You also need awareness of employment, copyright and intellectual property law, international legislation for multi-national work, when to involve law enforcement, and what written authority an engagement requires.
The ethics skill area covers the strong ethical standards that accurate threat intelligence demands and the CREST Code of Conduct, including the responsibilities it places on individuals and companies. Candidates outside the UK should still study the legal list, because it is part of the syllabus.
Technical cyber security
The final group checks that analysts understand the technology attackers use. It covers IPv4 and IPv6, TCP, UDP and ICMP, VPN protocols, and how adversaries use these protocols in ways that can reveal their capability and point towards attribution. Cryptography fundamentals include the difference between encryption and encoding and between symmetric and asymmetric encryption, along with common algorithms.
Vulnerability knowledge focuses on flaws in popular desktops, web servers and mobile devices, especially where public exploit code exists, plus zero-day exploits and suggesting mitigations. Intrusion vectors include spear phishing, watering holes and drive-by downloads, with awareness of attack pattern references such as CAPEC and OWASP. Command and control, data exfiltration techniques and attack attribution, including the use of VPNs, proxies and Tor to hide an attack's source, complete the technical picture. Knowledge of the current threat landscape and how it is changing is assessed through long-form answers.
How is the CRTIA exam structured?
According to CREST's Notes for Candidates, the exam is entirely written, with no practical element. It has two components that you sit in one session.
| Component | What you answer | Marks |
|---|---|---|
| Multiple choice | 120 questions, all compulsory, one mark each | 120 |
| Long form | Choose two of three written questions, 25 marks each | 50 |
| Time allowed | 3 hours in total for both components | - |
| Format | Closed book, no internet access, invigilated | - |
No marks are deducted for wrong multiple-choice answers, so leave nothing blank. Because both components share the same three hours, plan your time before you start: the long-form answers need structure, evidence and a clear conclusion, and they are hard to rush.

What happens on exam day
The exam is delivered at a Pearson VUE test centre of your choice, booked through the Pearson VUE website. Before it starts you will need suitable identification, such as a passport, driving licence or military ID. You will also sign a non-disclosure agreement, because CREST treats the exam content as confidential, and sign the CREST Code of Conduct.
An invigilator is present throughout. The invigilator does not assess your ability and cannot help with content, but can answer procedural questions and help if something goes wrong with the session. Reference material, internet access and chat or messaging systems are not allowed. CREST communicates results within 30 working days of the exam, so build that wait into any plans that depend on the result.
What score do you need to pass?
CREST's Notes for Candidates require 70% of the available marks in each component. That means at least 84 out of 120 marks in the multiple-choice paper and at least 35 out of 50 marks across your two long-form answers.
The two thresholds are separate. A very strong multiple-choice score cannot make up for weak long-form answers, and the reverse is also true. Candidates who fall short are told their scores in the components where they missed the 70% mark. CREST's certification page summarises the multiple-choice requirement as a two-thirds pass mark, so confirm the current rule on the exam page when you book.
Two worked examples
Imagine a candidate who scores 100 out of 120 in the multiple-choice paper but only 30 out of 50 in the long-form section. Their overall percentage looks healthy, yet they fail, because the long-form score is below 35. A second candidate who scores exactly 84 out of 120 and exactly 35 out of 50 passes, even though neither result feels comfortable. The lesson is simple: prepare both components with equal seriousness and never assume one can carry the other.
Which frameworks and methods come up most often?
Several models appear repeatedly across the syllabus, and knowing them well pays off in both components. Expect questions that ask you to apply them, not just name them.
- The cyber kill chain and MITRE ATT&CK for describing attacker tactics, techniques and procedures.
- The Diamond Model of intrusion analysis for linking adversary, capability, infrastructure and victim.
- Analysis of competing hypotheses and intelligence preparation of the environment for structured, bias-aware reasoning.
- The intelligence lifecycle and F3EAD for running an engagement from direction to dissemination.
- Source types such as OSINT, HUMINT and SIGINT, and how to grade the reliability of each source.
In the multiple-choice paper these frameworks usually appear as recognition and application: which phase an activity belongs to, which model fits a problem, or which source type a piece of information came from. In long-form answers you are expected to use them as tools. A strong answer might frame an adversary with the Diamond Model, map their behaviour to ATT&CK techniques, weigh competing explanations for an attack and then state a confidence level for your conclusion.
Practise explaining each framework in two or three sentences without notes, then applying it to a real, publicly reported incident. If you can do both, you are ready for most questions that draw on them.

How should you prepare for the exam?
CREST states plainly that the exam tests knowledge, experience and the ability to run threat intelligence engagements, and that it does not expect candidates to pass through self-study alone. Real project experience is the foundation, and study fills the gaps around it.
A practical plan looks like this:
- Read the syllabus line by line and rate yourself against each skill area, marking the ones you have never used at work.
- Work through CREST's recommended reading, which includes Richards Heuer's Psychology of Intelligence Analysis, the Diamond Model paper, MITRE ATT&CK resources and Michael Bazzell's Open Source Intelligence Techniques.
- Write timed long-form answers to realistic scenarios, such as scoping an engagement for a bank or assessing a new ransomware group, and review them for structure and caveats.
- Use timed practice questions to find weak areas in the multiple-choice topics, especially DNS, statistics, cryptography and legislation.
- Rehearse exam-day logistics: bring suitable photo ID, and expect to sign a non-disclosure agreement and the CREST Code of Conduct before you begin.
Build the plan around your experience
Your self-assessment decides where the time goes. An analyst from a technical security background often knows DNS, indicators and malware behaviour well but has less practice with source reliability grading, human sources, legislation and client management. An analyst from a police, military or government intelligence background may be the opposite, confident with analytic tradecraft and legal frameworks but less familiar with protocols, cryptography and command and control. Spend most of your study time on the groups you rated lowest, and use short refreshers for the rest.
Practise long-form answers properly
Long-form questions reward the same habits as good intelligence reports. Start with a clear bottom line that answers the question. Support it with evidence and explain how reliable that evidence is. State your confidence and the assumptions behind it, flag the gaps, and finish with practical recommendations. Choosing the two questions you can answer best is part of the skill, so read all three before committing.
After each practice answer, check it against the syllabus: did you cover the legal basis for collection, the audience for the product and the limitations of your analysis? Asking a colleague to review your answer as if they were the customer is one of the fastest ways to improve.
Use practice questions to find gaps
Practice questions are most useful as a diagnostic tool rather than a memory exercise. After each session, group your wrong answers by syllabus area and revisit the underlying topic instead of the individual question. Timed runs also teach you how long the multiple-choice paper really takes, so you can protect enough of the three hours for the long-form section. Avoid any source that claims to reproduce live exam questions: CREST requires candidates to keep exam content confidential, and memorised answers do not build the judgement the long-form section tests.
Common mistakes candidates make
Most failed attempts trace back to a small number of avoidable mistakes. The first is treating the exam as purely technical and neglecting the legal, ethical and management groups, which appear throughout both components. The second is poor time management, spending so long on the multiple-choice paper that the long-form answers become rushed outlines.
The third is answering the question you hoped for rather than the one asked, especially in long-form scenarios that specify a customer, sector or constraint. The fourth is presenting judgements without confidence levels, caveats or source reliability, which undermines otherwise good analysis. The last is relying on memory rather than method: frameworks such as the Diamond Model and analysis of competing hypotheses only earn marks when you apply them to the situation in front of you.
Is a threat intelligence certification worth it for your career?
For analysts who already do this work, a CREST registration gives employers and clients independent evidence that you can collect, analyse and report intelligence to a consistent standard within legal and ethical limits. That matters most in consultancies that deliver threat intelligence services and in organisations that buy them.
Typical job titles include cyber threat intelligence analyst, threat researcher and intelligence lead within a security operations or incident response team. The daily work mixes monitoring sources, writing assessments for technical and executive readers, and briefing colleagues who hunt for or respond to intrusions. Employers value analysts who state how confident they are in an assessment and why, because intelligence that overstates certainty leads to poor decisions.
The syllabus also covers regulator-mandated, intelligence-led testing schemes, and CREST's reading list points to the Bank of England's CBEST implementation guide and the European Central Bank's TIBER-EU framework. If your work touches financial-sector testing, that knowledge is directly useful. The qualification is valid for three years, which gives you a clear point to review how your skills and the threat landscape have moved on.
Where the registered level fits
CREST publishes separate documentation for a Practitioner Threat Intelligence Analyst qualification as well as the registered analyst exam. If you are earlier in your career and do not yet have the experience CREST expects for the registered level, compare the two syllabuses on the CREST website and choose the one that matches the work you do today.
If you are ready to test yourself, start with the syllabus areas you rated weakest, then take a timed practice run before booking your exam at a Pearson VUE test centre.
Frequently Asked Questions
Who is the CREST Registered Threat Intelligence Analyst exam for?
It is aimed at people who are part of a team delivering threat intelligence services. CREST expects at least two years of experience collecting, analysing and documenting threat intelligence, and candidates may come from information security, private security, police, military or intelligence backgrounds.
How many questions are on the threat intelligence analyst exam?
The multiple-choice paper has 120 compulsory questions worth one mark each. The long-form section presents three written questions, and you answer two of them for 25 marks each. You have 3 hours in total for both components. Plan your time so both long-form answers get enough attention.
What is the passing score for the exam?
CREST's Notes for Candidates require 70% in each component: at least 84 out of 120 marks in the multiple-choice paper and at least 35 out of 50 marks in the long-form answers. A high score in one component cannot make up for the other.
How long is the CREST threat intelligence analyst qualification valid?
CREST states that the Registered Threat Intelligence Analyst qualification is valid for three years. Exam results are communicated within 30 working days of completing the exam, so allow for that gap when you plan around a job application or renewal.
Where do you take the exam and what should you bring?
The exam is delivered at a Pearson VUE test centre of your choice. Bring suitable photo ID such as a passport or driving licence, and expect to sign a non-disclosure agreement and the CREST Code of Conduct. Costs depend on your country booking.
- CREST Certification |
- CREST Threat Intelligence Certification |
- CRTIA Online Test |
- CRTIA Questions |
- CRTIA Quiz |
- CRTIA |
- CREST Registered Threat Intelligence Analyst Certification |
- Registered Threat Intelligence Analyst Practice Test |
- Registered Threat Intelligence Analyst Study Guide |
- CREST CRTIA Question Bank |
- Registered Threat Intelligence Analyst Certification Mock Test |
- Registered Threat Intelligence Analyst Simulator |
- Registered Threat Intelligence Analyst Mock Exam |
- CREST Registered Threat Intelligence Analyst Questions |
- Registered Threat Intelligence Analyst |
- CREST Registered Threat Intelligence Analyst Practice Test |
- CRTIA Syllabus |
- Registered Threat Intelligence Analyst Books |
- Registered Threat Intelligence Analyst Certification Syllabus |
- CREST CRTIA Books |
- CREST Registered Threat Intelligence Analyst Training |
- Registered Threat Intelligence Analyst Sample Questions |
- CREST CRTIA Practice Test Free |
- CRTIA Practice Test |
- CRTIA Practice Exam
