CREST CPTIA 考試概覽:
| 認證廠商: | CREST |
| 考試名稱: | CREST從業級威脅情報分析師 |
| 考試代碼: | CPTIA |
| 相關認證: | CREST註冊級威脅情報分析師(CRTIA) CREST認證威脅情報經理(CCTIM) |
| 實際考試題數: | 120 |
| 考試費用: | 275英鎊 / 360美元(依地區有所調整) |
| 證照有效期限: | 3年 |
| 考試形式: | 選擇題, 情境式試題 |
| 考試時間: | 120 minutes |
| 及格分數: | 66% |
| 支援語言: | English |
| 推薦課程: | CREST認可訓練機構 |
| 考試報名: | 官方考試頁面 Pearson VUE報名註冊 |
| 範例考題: | CREST CPTIA 範例考題 |
| 考試方式: | 採電腦測驗形式,於全球Pearson VUE考場辦理 |
| 必備條件: | 無強制先修條件;建議具備基礎資安知識或CompTIA Security+ / Network+認同等級能力 |
| 官方大綱網址: | https://www.crest-approved.org/certification-careers/crest-certifications/crest-practitioner-threat-intelligence-analyst/ |
CREST CPTIA 考試大綱主題:
| 章節 | 權重 | 目標 |
|---|---|---|
| 主題 1: 法律與倫理考量 | 16% | - 倫理原則與專業行為規範 - 敏感與機密資訊的處理 - 資料保護與隱私權 - 法律架構與法規(GDPR、DPA等) - CREST行為準則 |
| 主題 2: 方向制定與成果審查 | 17% | - 辨識情報缺口 - 職權範圍與適用邊界 - 定義情報需求(PIR、SIR) - 規劃與優先順序安排 - 審查情報成果 |
| 主題 3: 情報成果傳遞與分享 | 16% | - 資訊分級協定(TLP)與機密等級處理 - 情報分享協定與標準 - 結構化與非結構化報告 - 情報成果的類型 - 依接收對象調整內容(戰術面、作業面、策略面) |
| 主題 4: 資料分析 | 17% | - 假設、事實與推論 - 表達可能性與確定程度 - 模式辨識與趨勢分析 - 假說建立與驗證 - 認知偏誤與分析誤差 - 分析技術與結構化方法 |
| 主題 5: 資料蒐集 | 17% | - 搜尋技巧與查詢語句建構 - 來源可信度與評估 - 情報來源類型(OSINT、HUMINT、TECHINT) - 蒐集作業中的操作安全(OPSEC) - 蒐集規劃與管理 |
| 主題 6: 核心概念 | 17% | - 分析模型與攻擊生命週期 - 威脅來源類型與分類 - 情報循環與架構 - 威脅途徑、弱點與風險 - 資料、資訊與情報的關係 - 專有名詞與定義 - 威脅情報的目標 |
最新的 CREST Practitioner CPTIA 免費考試真題:
1. Walter and Sons Company has faced major cyber attacks and lost confidential data. The company has decided to concentrate more on the security rather than other resources. Therefore, they hired Alice, a threat analyst, to perform data analysis. Alice was asked to perform qualitative data analysis to extract useful information from collected bulk data.
Which of the following techniques will help Alice to perform qualitative data analysis?
A) Finding links between data and discover threat-related information
B) Brainstorming, interviewing, SWOT analysis, Delphi technique, and so on
C) Numerical calculations, statistical modeling, measurement, research, and so on.
D) Regression analysis, variance analysis, and so on
2. Sarah is a security operations center (SOC) analyst working at JW Williams and Sons organization based in Chicago. As a part of security operations, she contacts information providers (sharing partners) for gathering information such as collections of validated and prioritized threat indicators along with a detailed technical analysis of malware samples, botnets, DDoS attack methods, and various other malicious tools. She further used the collected information at the tactical and operational levels.
Sarah obtained the required information from which of the following types of sharing partner?
A) Providers of comprehensive cyber-threat intelligence
B) Providers of threat data feeds
C) Providers of threat indicators
D) Providers of threat actors
3. During the process of detecting and containing malicious emails, incident responders should examine the originating IP address of the emails.
The steps to examine the originating IP address are as follow:
1. Search for the IP in the WHOIS database
2. Open the email to trace and find its header
3. Collect the IP address of the sender from the header of the received mail
4. Look for the geographic address of the sender in the WHOIS database
Identify the correct sequence of steps to be performed by the incident responders to examine originating IP address of the emails.
A) 1-->3-->2-->4
B) 4-->1-->2-->3
C) 2-->1-->4-->3
D) 2-->3-->1-->4
4. Jason is an incident handler dealing with malware incidents. He was asked to perform memory dump analysis in order to collect the information about the basic functionality of any program. As a part of his assignment, he needs to perform string search analysis to search for the malicious string that could determine harmful actions that a program can perform. Which of the following string-searching tools Jason needs to use to do the intended task?
A) BinText
B) PEView
C) Process Explorer
D) Dependency Walker
5. A threat analyst wants to incorporate a requirement in the threat knowledge repository that provides an ability to modify or delete past or irrelevant threat data.
Which of the following requirement must he include in the threat knowledge repository to fulfil his needs?
A) Searchable functionality
B) Evaluating performance
C) Data management
D) Protection ranking
問題與答案:
| 問題 #1 答案: B | 問題 #2 答案: A | 問題 #3 答案: D | 問題 #4 答案: A | 問題 #5 答案: C |

下載最新試用版
1305位客戶反饋
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。








106.188.127.* -
你們的考古題對于沒有太多時間做考試準備的我來說非常好,讓我花了很少的時間和精力就通過了 CPTIA 考試。