The CTIA exam (prefix 312-85) is a 2-hour, 50-question multiple-choice test with a published passing score of 70%, per EC-Council's certification page. The CTIA v2 exam blueprint defines eight weighted domains, with Data Collection and Processing the largest at 24%, tracing the full threat intelligence lifecycle from planning and requirements through collection, analysis, and reporting to threat hunting and SOC integration. EC-Council's marketing positions the program at mid- to high-level cybersecurity professionals; its enrollment guidance states both a two-year and a three-year experience figure, so confirm the current placement guidance directly. If you are earlier in your career, Threat Intelligence Essentials (TIE) is EC-Council's beginner-level entry point into the same field.
What the CTIA credential covers
CTIA is EC-Council's specialist-level certification for people who collect, analyze, and disseminate threat intelligence. It follows the complete threat intelligence lifecycle and trains four intelligence types: strategic, operational, tactical, and technical.
EC-Council describes the program as specialist-level and aimed at individuals involved in collecting, analyzing, and sharing threat intelligence information. The course focuses on turning raw data into actionable intelligence used to prevent, detect, and monitor attacks.
The syllabus spans threat intelligence fundamentals, threat actors and attack frameworks such as APTs, the Cyber Kill Chain, MITRE ATT&CK, and the Diamond Model, program planning, data collection, analysis, reporting and sharing, threat hunting, and intelligence work inside SOC operations, incident response, and risk management.
The training is deliberately hands-on: EC-Council states that 40% of training time goes to labs, with 27 hands-on labs, a 350-plus-page lab manual, and coverage of more than 200 threat intelligence tools.
Exam format and the facts that matter
The CTIA exam (prefix 312-85) has 50 multiple-choice questions with a 2-hour duration and a published passing score of 70%, available through EC-Council's ECC Exam Center.
These figures come from EC-Council's official certification page, so you can plan pacing precisely: two hours for 50 questions is roughly 2.4 minutes per question. The program page's own sample questions give you a preview of the scenario style.
The exam voucher is included with the CTIA program package, together with courseware and lab access. Scheduling runs through EC-Council's exam portal rather than a third-party test network.
- Exam prefix: 312-85
- Questions: 50, multiple choice
- Duration: 2 hours
- Passing: 70%
- Availability: EC-Council's ECC Exam Center
Sources: Certified Threat Intelligence Analyst — https://cert.eccouncil.org/certified-threat-intelligence-analyst.html; Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council — Program page, exam details, course outline, FAQs
The eight exam domains and their weights
The CTIA v2 blueprint defines eight weighted domains, from Intelligence (12%) through Data Collection and Processing (24%) — the heaviest — down to Threat Hunting and Detection (6%) and intelligence in SOC operations, incident response, and risk management (6%).
The blueprint is the exam's scope authority. EC-Council's candidate FAQ states that official courseware and training are developed independently of exam content, so use the blueprint's domain list — not the course module list — as your study checklist.
The domains mirror the lifecycle in order: requirements come before collection, collection before analysis, and analysis before reporting. Later domains then apply that pipeline to threat hunting and to security operations.
The blueprint document is labeled version 2 (v2) on its own title pages, so you are reading the current published edition. The table gives the exact weights and the topic areas each domain lists.
| Domain | Weight | Topics listed in the blueprint |
|---|---|---|
| 1. Intelligence | 12% | CTI concepts, lifecycle and frameworks, TIPs, cloud environment, future trends |
| 2. Cyber Threats and Attack Frameworks | 8% | Cyber threats, APTs, Cyber Kill Chain, MITRE ATT&CK and Diamond Model, IoCs |
| 3. Requirements, Planning, Direction, and Review | 14% | Threat landscape, requirements analysis, program planning, team building, sharing, review |
| 4. Data Collection and Processing | 24% | Collection, collection management, feeds and sources, acquisition, bulk data, processing and exploitation, cloud enrichment |
| 5. Data Analysis | 16% | Analysis techniques, threat analysis and process, fine-tuning, evaluation, runbooks and knowledge base, tools |
| 6. Reporting of Intelligence | 14% | Reports, dissemination, sharing relationships, delivery mechanisms, sharing platforms, acts and regulations, Python scripting |
| 7. Threat Hunting and Detection | 6% | Threat hunting concepts, automation |
| 8. Threat Intelligence in SOC Operations, Incident Response, and Risk Management | 6% | SOC operations, risk management, incident response |
Sources: CTIA Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/02/CTIA-v2-Exam-Blueprint.pdf; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:
Who can apply — and one discrepancy to check
EC-Council's program marketing positions CTIA for mid- to high-level cybersecurity professionals, and states that people holding EC-Council's CEH or CND certifications can enroll. Its enrollment guidance is inconsistent — one section asks for a minimum of three years of experience, while FAQ and prerequisite answers say at least two years in cybersecurity, IT, or a related field.
Both figures appear on the program's marketing and FAQ pages, not on the exact certification page, which publishes exam policies instead. Treat them as training-placement guidance rather than a formal exam eligibility threshold, and confirm the current guidance with EC-Council before committing. In practice, the program assumes you already work in information security, network security, incident response, or a closely related field.
If your background is shorter than this guidance suggests, treat it as a signal to build foundational experience first — a later section covers the beginner-friendly alternative.
Training formats, duration, and cost
The program is delivered as a 3-day (24-hour) course in three formats: iLearn self-study, iWeek live online, and in-person training through a partner. The exam voucher is bundled with the program, and cost varies by the delivery mode you choose.
iLearn is an asynchronous, video-based self-study environment; iWeek is live, online, and instructor-led; the training-partner option is in-person with certified instructors.
EC-Council does not publish a single certification price. The fee depends on the mode you select, so request current pricing from EC-Council's website or a career advisor before budgeting.
How to prepare, based on the official blueprint
Use the v2 blueprint's eight domains as your checklist and weight your time by the published percentages. The issuer FAQ states that courseware and exams are developed independently, so the blueprint — not the course module list — defines what to study.
A practical sequence, as advice rather than an official requirement: start with Domain 1's vocabulary and the lifecycle, because every later domain assumes it. Then learn Domain 2's frameworks — APTs, Cyber Kill Chain, MITRE ATT&CK, the Diamond Model, and indicators of compromise — well enough to say what each one is for.
Work Domains 3 through 6 as one continuous pipeline from requirement to delivered report. By blueprint weight, Data Collection and Processing (24%) and Data Analysis (16%) deserve the largest share of your study time.
The program page includes a short set of self-check sample questions covering data analysis types, indicators of compromise, threat actor categories, and the Cyber Kill Chain — a useful calibration of question style before you sit the exam.
For named techniques such as statistical analysis, ACH, SACH, and YARA-based sharing, know each technique's purpose and when it applies. The brochure and courseware carry the technical depth; this guide does not reproduce it.
- Learn the lifecycle stages and the four intelligence types first; they anchor everything else
- Trace Domains 3 through 6 as one pipeline: requirement, collection, analysis, report
- Use the program page's sample questions to gauge the exam's scenario style
- Check for blueprint updates before you book, since EC-Council revises exams and releases new blueprints over time
Sources: CTIA Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/02/CTIA-v2-Exam-Blueprint.pdf; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:; Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council — Program page, exam details, course outline, FAQs
Practice: map a week of analyst work to the lifecycle
Match each activity to the blueprint domain whose title names that lifecycle phase, using the v2 domain list as your map.
The lifecycle is the exam's backbone, and the domain titles give you a reliable anchor for classifying any described activity. The exercise below uses only the blueprint domains shown earlier.
Practice
A threat intelligence team at a mid-sized bank does the following in one week. Match each activity to the CTIA blueprint domain where it belongs: (1) interview the fraud team and write a prioritized list of intelligence requirements; (2) pull indicators from external feeds and internal email-gateway logs, then normalize the combined data; (3) evaluate competing explanations for an anomalous login pattern; (4) send a tactical report to the SOC and a risk summary to management.
Show answer
Activity 1 belongs to Domain 3 (Requirements, Planning, Direction, and Review). Activity 2 belongs to Domain 4 (Data Collection and Processing). Activity 3 belongs to Domain 5 (Data Analysis). Activity 4 belongs to Domain 6 (Reporting of Intelligence).
Each domain title names its phase of work. Gathering requirements from stakeholders and prioritizing them is planning and direction work, the scope of Domain 3. Pulling indicators from external feeds and internal sources, then structuring the combined data, matches Domain 4's collection, feeds and sources, and processing topics. Evaluating competing explanations for an anomaly is analysis, Domain 5. Delivering a tactical report to the SOC and a risk summary to management is reporting and dissemination, Domain 6. If you hesitated on any item, re-read the domain table above.
Sources: CTIA Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/02/CTIA-v2-Exam-Blueprint.pdf
Not at CTIA level yet? Start with Threat Intelligence Essentials
EC-Council's Threat Intelligence Essentials (TIE) is the beginner-level entry into the same field, with no IT or cybersecurity experience required, and it feeds the recommended path toward CTIA.
TIE covers foundational threat intelligence terminology, intelligence types, the threat landscape, data collection and sources, threat intelligence platforms, analysis, hunting, sharing, and intelligence in incident response. Its exam (code 112-54) has 75 multiple-choice questions over 2 hours.
EC-Council's own learning-path guidance places TIE first, then the Certified Cybersecurity Technician (CCT), then CEH and CND, before advancing to CTIA. If your background is shorter than the CTIA experience expectations, that sequence is the sourced route in.
Sources: Threat Intelligence Course | TIE Certification | EC-Council — Course outline and exam details
Your next steps
Confirm the enrollment guidance, pick a training format, study by blueprint weight, and calibrate with the official sample questions before booking.
A short checklist to close, built from the verified facts above.
- Confirm the current enrollment guidance with EC-Council, since the program page states both two and three years of experience
- Choose a delivery mode (iLearn, iWeek, or in-person) and request current pricing, as cost varies by mode
- Weight your study time by the v2 blueprint percentages, starting with Data Collection and Processing at 24%
- Work through the program page's sample questions to learn the scenario style
- If you are early in your career, start with TIE and follow the CCT, CEH, and CND path toward CTIA
Sources: Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council — Program page, exam details, course outline, FAQs; Threat Intelligence Course | TIE Certification | EC-Council — Course outline and exam details; Certified Threat Intelligence Analyst — https://cert.eccouncil.org/certified-threat-intelligence-analyst.html; CTIA Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/02/CTIA-v2-Exam-Blueprint.pdf
Sources
Facts checked:
- Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council
- Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council
- Threat Intelligence Course | TIE Certification | EC-Council
- Certified Threat Intelligence Analyst
- CTIA Blueprint
- EC-Council candidate FAQ: exam preparation and blueprint updates
