CREST Practitioner Threat Intelligence Analyst (CPTIA) Certification Sample Questions

Practitioner Threat Intelligence Analyst Dumps, CPTIA Dumps, CPTIA PDF, Practitioner Threat Intelligence Analyst VCE, CREST CPTIA VCE, CREST Practitioner Threat Intelligence Analyst PDFThe purpose of this Sample Question Set is to provide you with information about the CREST Practitioner Threat Intelligence Analyst exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the CPTIA certification test. To get familiar with real exam environment, we suggest you try our Sample CREST Practitioner Threat Intelligence Analyst Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual CREST Practitioner Threat Intelligence Analyst (CPTIA) certification exam.

These sample questions are simple and basic questions that represent likeness to the real CREST CPTIA exam questions. To assess your readiness and performance with real time scenario based questions, we suggest you prepare with our Premium CREST Practitioner Threat Intelligence Analyst Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

CREST CPTIA Sample Questions:

01. Which two actions should an analyst take to preserve OPSEC when performing intelligence collection?
(Choose two.)
a) Always use your real LinkedIn profile to gain trust
b) Use anonymized browsing environments (e.g., Tails, VMs)
c) Store results on an open shared drive (e.g., a team folder)
d) Use burner identities for registration
 
02. An analyst is investigating a domain used in a phishing campaign and needs to establish the date the domain was registered and which registrar issued it.
Which source provides that information directly?
a) The organization resolver logs showing which internal hosts queried the domain
b) A passive DNS record showing the addresses the domain has resolved to over time
c) The document metadata embedded in the phishing attachment itself
d) A sandbox analysis report describing the attachment behavior at runtime
e) A WHOIS lookup of the domain registration record
 
03. Why should OPSEC be maintained during online collection from adversary-controlled forums?
a) To prevent exposing the analyst’s identity or organization
b) To maximize open engagement with threat actors
c) To increase threat visibility through public search
d) To test web application firewall rules on collection hosts
 
04. Which of the following best describes the function of TAXII in threat intelligence sharing?
a) It transforms threat indicators into graphical reports
b) It encrypts payloads using proprietary algorithms
c) It scans internal file systems for malware
d) It defines a transport protocol for exchanging STIX data
 
05. In the Cyber Kill Chain, what phase typically follows initial delivery?
a) Reconnaissance
b) Installation
c) Exploitation
d) Actions on Objectives
 
06. To maintain OPSEC, threat intelligence analysts should avoid using __________ when accessing adversary forums.
a) corporate IP addresses
b) sandbox browsers
c) virtual machines
d) burner credentials
 
07. Which of the following regulations enforces data privacy and processing rules in the UK and EU?
a) Network and Information Systems Regulations
b) Data Minimization Directive
c) General Data Protection Regulation (GDPR)
d) UK Freedom of Press Act
 
08. What is the primary purpose of a Terms of Reference (ToR) document in a threat intelligence engagement?
a) To list the organizational policies and procedures already approved
b) To define scope, objectives, and responsibilities of the engagement
c) To summarize the technical controls in place
d) To outline budget constraints only
 
09. What are two ways to mitigate the impact of known intelligence gaps?
(Choose two.)
a) Apply confidence levels to findings
b) Remove all related indicators
c) Annotate reports with assumptions
d) Ignore and defer analysis
 
10. Who is primarily responsible for approving the Terms of Reference in a threat intelligence engagement?
a) External threat actor profiling team
b) IT help desk manager
c) SOC analyst handling the detection queue
d) Project sponsor or client-side stakeholder

Answers:

Question: 01
Answer: b, d
Question: 02
Answer: e
Question: 03
Answer: a
Question: 04
Answer: d
Question: 05
Answer: c
Question: 06
Answer: a
Question: 07
Answer: c
Question: 08
Answer: b
Question: 09
Answer: a, c
Question: 10
Answer: d

Note: For any error in CREST Practitioner Threat Intelligence Analyst (CPTIA) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.8 / 5 (110 votes)