Study Guide

EC-Council CTIA Study Guide: Exam Format and Preparation

Prepare for the EC-Council CTIA exam: verified format facts, the eight blueprint domains with weights, and a practical lifecycle exercise.

Updated September 20269 min readStudy GuideCEH Exam
Gabrielle Wallace

Gabrielle Wallace

CEH Exam Editorial Team

The CTIA exam (prefix 312-85) is a 2-hour, 50-question multiple-choice test with a published passing score of 70%, per EC-Council's certification page. The CTIA v2 exam blueprint defines eight weighted domains, with Data Collection and Processing the largest at 24%, tracing the full threat intelligence lifecycle from planning and requirements through collection, analysis, and reporting to threat hunting and SOC integration. EC-Council's marketing positions the program at mid- to high-level cybersecurity professionals; its enrollment guidance states both a two-year and a three-year experience figure, so confirm the current placement guidance directly. If you are earlier in your career, Threat Intelligence Essentials (TIE) is EC-Council's beginner-level entry point into the same field.

What the CTIA credential covers

CTIA is EC-Council's specialist-level certification for people who collect, analyze, and disseminate threat intelligence. It follows the complete threat intelligence lifecycle and trains four intelligence types: strategic, operational, tactical, and technical.

EC-Council describes the program as specialist-level and aimed at individuals involved in collecting, analyzing, and sharing threat intelligence information. The course focuses on turning raw data into actionable intelligence used to prevent, detect, and monitor attacks.

The syllabus spans threat intelligence fundamentals, threat actors and attack frameworks such as APTs, the Cyber Kill Chain, MITRE ATT&CK, and the Diamond Model, program planning, data collection, analysis, reporting and sharing, threat hunting, and intelligence work inside SOC operations, incident response, and risk management.

The training is deliberately hands-on: EC-Council states that 40% of training time goes to labs, with 27 hands-on labs, a 350-plus-page lab manual, and coverage of more than 200 threat intelligence tools.

Sources: Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council — Program page, exam details, course outline, FAQs

Exam format and the facts that matter

The CTIA exam (prefix 312-85) has 50 multiple-choice questions with a 2-hour duration and a published passing score of 70%, available through EC-Council's ECC Exam Center.

These figures come from EC-Council's official certification page, so you can plan pacing precisely: two hours for 50 questions is roughly 2.4 minutes per question. The program page's own sample questions give you a preview of the scenario style.

The exam voucher is included with the CTIA program package, together with courseware and lab access. Scheduling runs through EC-Council's exam portal rather than a third-party test network.

  • Exam prefix: 312-85
  • Questions: 50, multiple choice
  • Duration: 2 hours
  • Passing: 70%
  • Availability: EC-Council's ECC Exam Center

Sources: Certified Threat Intelligence Analyst — https://cert.eccouncil.org/certified-threat-intelligence-analyst.html; Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council — Program page, exam details, course outline, FAQs

The eight exam domains and their weights

The CTIA v2 blueprint defines eight weighted domains, from Intelligence (12%) through Data Collection and Processing (24%) — the heaviest — down to Threat Hunting and Detection (6%) and intelligence in SOC operations, incident response, and risk management (6%).

The blueprint is the exam's scope authority. EC-Council's candidate FAQ states that official courseware and training are developed independently of exam content, so use the blueprint's domain list — not the course module list — as your study checklist.

The domains mirror the lifecycle in order: requirements come before collection, collection before analysis, and analysis before reporting. Later domains then apply that pipeline to threat hunting and to security operations.

The blueprint document is labeled version 2 (v2) on its own title pages, so you are reading the current published edition. The table gives the exact weights and the topic areas each domain lists.

DomainWeightTopics listed in the blueprint
1. Intelligence12%CTI concepts, lifecycle and frameworks, TIPs, cloud environment, future trends
2. Cyber Threats and Attack Frameworks8%Cyber threats, APTs, Cyber Kill Chain, MITRE ATT&CK and Diamond Model, IoCs
3. Requirements, Planning, Direction, and Review14%Threat landscape, requirements analysis, program planning, team building, sharing, review
4. Data Collection and Processing24%Collection, collection management, feeds and sources, acquisition, bulk data, processing and exploitation, cloud enrichment
5. Data Analysis16%Analysis techniques, threat analysis and process, fine-tuning, evaluation, runbooks and knowledge base, tools
6. Reporting of Intelligence14%Reports, dissemination, sharing relationships, delivery mechanisms, sharing platforms, acts and regulations, Python scripting
7. Threat Hunting and Detection6%Threat hunting concepts, automation
8. Threat Intelligence in SOC Operations, Incident Response, and Risk Management6%SOC operations, risk management, incident response

Sources: CTIA Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/02/CTIA-v2-Exam-Blueprint.pdf; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:

Who can apply — and one discrepancy to check

EC-Council's program marketing positions CTIA for mid- to high-level cybersecurity professionals, and states that people holding EC-Council's CEH or CND certifications can enroll. Its enrollment guidance is inconsistent — one section asks for a minimum of three years of experience, while FAQ and prerequisite answers say at least two years in cybersecurity, IT, or a related field.

Both figures appear on the program's marketing and FAQ pages, not on the exact certification page, which publishes exam policies instead. Treat them as training-placement guidance rather than a formal exam eligibility threshold, and confirm the current guidance with EC-Council before committing. In practice, the program assumes you already work in information security, network security, incident response, or a closely related field.

If your background is shorter than this guidance suggests, treat it as a signal to build foundational experience first — a later section covers the beginner-friendly alternative.

Sources: Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council — Program page, exam details, course outline, FAQs

Training formats, duration, and cost

The program is delivered as a 3-day (24-hour) course in three formats: iLearn self-study, iWeek live online, and in-person training through a partner. The exam voucher is bundled with the program, and cost varies by the delivery mode you choose.

iLearn is an asynchronous, video-based self-study environment; iWeek is live, online, and instructor-led; the training-partner option is in-person with certified instructors.

EC-Council does not publish a single certification price. The fee depends on the mode you select, so request current pricing from EC-Council's website or a career advisor before budgeting.

Sources: Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council — Program page, exam details, course outline, FAQs

How to prepare, based on the official blueprint

Use the v2 blueprint's eight domains as your checklist and weight your time by the published percentages. The issuer FAQ states that courseware and exams are developed independently, so the blueprint — not the course module list — defines what to study.

A practical sequence, as advice rather than an official requirement: start with Domain 1's vocabulary and the lifecycle, because every later domain assumes it. Then learn Domain 2's frameworks — APTs, Cyber Kill Chain, MITRE ATT&CK, the Diamond Model, and indicators of compromise — well enough to say what each one is for.

Work Domains 3 through 6 as one continuous pipeline from requirement to delivered report. By blueprint weight, Data Collection and Processing (24%) and Data Analysis (16%) deserve the largest share of your study time.

The program page includes a short set of self-check sample questions covering data analysis types, indicators of compromise, threat actor categories, and the Cyber Kill Chain — a useful calibration of question style before you sit the exam.

For named techniques such as statistical analysis, ACH, SACH, and YARA-based sharing, know each technique's purpose and when it applies. The brochure and courseware carry the technical depth; this guide does not reproduce it.

  • Learn the lifecycle stages and the four intelligence types first; they anchor everything else
  • Trace Domains 3 through 6 as one pipeline: requirement, collection, analysis, report
  • Use the program page's sample questions to gauge the exam's scenario style
  • Check for blueprint updates before you book, since EC-Council revises exams and releases new blueprints over time

Sources: CTIA Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/02/CTIA-v2-Exam-Blueprint.pdf; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:; Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council — Program page, exam details, course outline, FAQs

Practice: map a week of analyst work to the lifecycle

Match each activity to the blueprint domain whose title names that lifecycle phase, using the v2 domain list as your map.

The lifecycle is the exam's backbone, and the domain titles give you a reliable anchor for classifying any described activity. The exercise below uses only the blueprint domains shown earlier.

Practice

A threat intelligence team at a mid-sized bank does the following in one week. Match each activity to the CTIA blueprint domain where it belongs: (1) interview the fraud team and write a prioritized list of intelligence requirements; (2) pull indicators from external feeds and internal email-gateway logs, then normalize the combined data; (3) evaluate competing explanations for an anomalous login pattern; (4) send a tactical report to the SOC and a risk summary to management.

Show answer

Activity 1 belongs to Domain 3 (Requirements, Planning, Direction, and Review). Activity 2 belongs to Domain 4 (Data Collection and Processing). Activity 3 belongs to Domain 5 (Data Analysis). Activity 4 belongs to Domain 6 (Reporting of Intelligence).

Each domain title names its phase of work. Gathering requirements from stakeholders and prioritizing them is planning and direction work, the scope of Domain 3. Pulling indicators from external feeds and internal sources, then structuring the combined data, matches Domain 4's collection, feeds and sources, and processing topics. Evaluating competing explanations for an anomaly is analysis, Domain 5. Delivering a tactical report to the SOC and a risk summary to management is reporting and dissemination, Domain 6. If you hesitated on any item, re-read the domain table above.

Sources: CTIA Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/02/CTIA-v2-Exam-Blueprint.pdf

Not at CTIA level yet? Start with Threat Intelligence Essentials

EC-Council's Threat Intelligence Essentials (TIE) is the beginner-level entry into the same field, with no IT or cybersecurity experience required, and it feeds the recommended path toward CTIA.

TIE covers foundational threat intelligence terminology, intelligence types, the threat landscape, data collection and sources, threat intelligence platforms, analysis, hunting, sharing, and intelligence in incident response. Its exam (code 112-54) has 75 multiple-choice questions over 2 hours.

EC-Council's own learning-path guidance places TIE first, then the Certified Cybersecurity Technician (CCT), then CEH and CND, before advancing to CTIA. If your background is shorter than the CTIA experience expectations, that sequence is the sourced route in.

Sources: Threat Intelligence Course | TIE Certification | EC-Council — Course outline and exam details

Your next steps

Confirm the enrollment guidance, pick a training format, study by blueprint weight, and calibrate with the official sample questions before booking.

A short checklist to close, built from the verified facts above.

  • Confirm the current enrollment guidance with EC-Council, since the program page states both two and three years of experience
  • Choose a delivery mode (iLearn, iWeek, or in-person) and request current pricing, as cost varies by mode
  • Weight your study time by the v2 blueprint percentages, starting with Data Collection and Processing at 24%
  • Work through the program page's sample questions to learn the scenario style
  • If you are early in your career, start with TIE and follow the CCT, CEH, and CND path toward CTIA

Sources: Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council — Program page, exam details, course outline, FAQs; Threat Intelligence Course | TIE Certification | EC-Council — Course outline and exam details; Certified Threat Intelligence Analyst — https://cert.eccouncil.org/certified-threat-intelligence-analyst.html; CTIA Blueprint — https://cert.eccouncil.org/wp-content/uploads/2024/02/CTIA-v2-Exam-Blueprint.pdf

Sources

Facts checked:

Next steps

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for EC-Council Certified Threat Intelligence Analyst (CTIA).

Is CTIA suitable for beginners?
No. EC-Council describes CTIA as a specialist-level program for mid- to high-level professionals with existing cybersecurity or IT experience. Beginners should start with Threat Intelligence Essentials (TIE), which requires no prior experience, and follow the CCT, CEH, and CND path.
How much does the CTIA certification cost?
EC-Council does not publish a single price. The cost differs depending on the training mode you select — in-person, iLearn, or iWeek — and the exam voucher is included in the program package. Check EC-Council's website or a career advisor for current figures.
How long does the training take?
The program is a 3-day, 24-hour training session delivered with exam preparation study materials, followed by the 2-hour, 50-question exam. Self-study lets you spread those 24 hours across your own schedule.
What jobs does CTIA support?
EC-Council lists roles such as Cyber Threat Intelligence Analyst, Cyber Threat Hunter, Cyber Threat Intelligence Associate/Researcher/Consultant, SOC Threat Intelligence Analyst, Cyber Threat Intelligence Engineer/Specialist/Lead/Manager, and threat intelligence management positions.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.