CREST CPTIA Exam Overview:
| Certification Vendor: | CREST |
| Exam Name: | CREST Practitioner Threat Intelligence Analyst (CPTIA) Examination |
| Exam Number: | CPTIA |
| Available Languages: | English |
| Related Certifications: | CREST Registered Threat Intelligence Analyst (CRTIA) CREST Certified Threat Intelligence Analyst (CCTIA) |
| Exam Format: | Practical scenario-based assessment, Written analysis and reporting tasks, Multiple-choice questions (varies by delivery format) |
| Recommended Training: | CREST Practitioner Threat Intelligence Training Providers |
| Exam Registration: | CREST Official Website |
| Sample Questions: | CREST CPTIA Sample Questions |
| Exam Way: | Typically delivered as a proctored assessment through CREST-approved examination centres or approved remote proctoring providers, depending on region and provider arrangements. |
| Pre Condition: | No strict mandatory prerequisite, but practical experience in cybersecurity, incident response, or threat intelligence is strongly recommended. |
| Official Syllabus URL: | https://www.crest-approved.org/ |
CREST CPTIA Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Threat Analysis and Frameworks | - Analytical methodologies
|
| Topic 2: Reporting and Dissemination | - Stakeholder communication
|
| Topic 3: Data Collection and Sources | - OSINT and technical collection
|
| Topic 4: Legal, Ethical, and Operational Considerations | - Legal and compliance
|
| Topic 5: Threat Intelligence Fundamentals | - Types of threat intelligence
|
CREST Practitioner Threat Intelligence Analyst Sample Questions:
1. Dan is a newly appointed information security professional in a renowned organization. He is supposed to follow multiple security strategies to eradicate malware incidents. Which of the following is not considered as a good practice for maintaining information security and eradicating malware incidents?
A) Do not download or execute applications from third-party sources
B) Do not open files with file extensions such as .bat, .com, ,exe, .pif, .vbs, and so on
C) Do not click on web browser pop-up windows
D) Do not download or execute applications from trusted sources
2. Darwin is an attacker residing within the organization and is performing network sniffing by running his system in promiscuous mode. He is capturing and viewing all the network packets transmitted within the organization. Edwin is an incident handler in the same organization.
In the above situation, which of the following Nmap commands Edwin must use to detect Darwin's system that is running in promiscuous mode?
A) nmap --script hostmap
B) nmap -sU -p 500
C) nmap --script=sniffer-detect [Target IP Address/Range of IP addresses]
D) nmap -sV -T4 -O -F -version-light
3. Joe works as a threat intelligence analyst with Xsecurity Inc. He is assessing the TI program by comparing the project results with the original objectives by reviewing project charter. He is also reviewing the list of expected deliverables to ensure that each of those is delivered to an acceptable level of quality.
Identify the activity that Joe is performing to assess a TI program's success or failure.
A) Identifying areas of further improvement
B) Conducting a gap analysis
C) Determining the costs and benefits associated with the program
D) Determining the fulfillment of stakeholders
4. Allan performed a reconnaissance attack on his corporate network as part of a red-team activity. He scanned the IP range to find live host IP addresses. What type of technique did he use to exploit the network?
A) DNS foot printing
B) Ping sweeping
C) Social engineering
D) Port scanning
5. XYZ Inc. was affected by a malware attack and James, being the incident handling and response (IH&R) team personnel handling the incident, found out that the root cause of the incident is a backdoor that has bypassed the security perimeter due to an existing vulnerability in the deployed firewall. James had contained the spread of the infection and removed the malware completely. Now the organization asked him to perform incident impact assessment to identify the impact of the incident over the organization and he was also asked to prepare a detailed report of the incident.
Which of the following stages in IH&R process is James working on?
A) Notification
B) Eradication
C) Evidence gathering and forensics analysis
D) Post-incident activities
Solutions:
| Question # 1 Answer: D | Question # 2 Answer: C | Question # 3 Answer: B | Question # 4 Answer: B | Question # 5 Answer: D |

We're so confident of our products that we provide no hassle product exchange.


By Murray


