Practitioner Threat Intelligence Analyst
CREST logo

Practitioner Threat Intelligence Analyst

CPTIA

Validate your ability to analyze threat intelligence data and operationalize cyber threat intelligence (CTI) for organizational defense with this CREST certification.

Exam syllabus, organized by domain

Try a real question

Sample Practitioner Threat Intelligence Analyst exam question

Answer this question the same way you would on exam day. No sign-up needed — one random question, three tries to swap it out.

MasterThreat Intelligence Concepts and Principles

Review the text. Is this operational or tactical intelligence? (Single Select)

text
INTELLIGENCE PRODUCT: 'Detection guidance for IcedID infection: Look for registry key modification at HKCU\Software\Microsoft\Windows\CurrentVersion\Run\[random]. Scheduled task named 'Updater' with binary path containing 'windowsupdate.exe' in %APPDATA%. Network detection: HTTP POST requests to domains with pattern *.xyz using non-standard User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:60.0). Add YARA rule to detect packed IcedID DLLs: rule IcedID_Packed { strings: $a = {4D 5A 90 00} condition: $a at 0 }.'

Frequently asked questions

Key facts about the Practitioner Threat Intelligence Analyst certification and how to prepare for it.

Skills & Requirements

What you need to know before attempting the Practitioner Threat Intelligence Analyst exam.