CPTIA - Reflection
Overview
So a few days ago I successfully passed the CREST Practitioner Threat Intelligence Analyst certification exam, taking me a little over 30 minuites (you’re allowed up to 120 minuites) to answer 120 questions.
The exam itself was a combination of multiple choice answers and some free form reasoning, and as a result was very stragithforward if you understand what the questions are asking. The thing to remember with CREST, they examine based on experience, the general idea being that they offer no training, you have to use the exam syllabus to assess whether you have the knowledge to pass the exam, then go and sit the exam.
What training do I think you’d need to pass if you have no intelligence background?
Ordinarily, you’d get the knowledge and experience from industry, I got mine from Policing. I worked on intelligence teams where I learned about the intelligence cycle, open source intelligence (OSINT), data collection, analysis, and dissemination. All that said, I had the intelligence experience, but not the cyber experience, so I needed to pursue training or guidance to shore up those knowledge areas. I ended up stumbling on a company called ArcX, and found that they have a certification pathway called ArcX Threat Intelligence Practitioner.
I decided to buy the course and went through it, looking back at the course on the other side of the exam, it prepares you very well for what you’ll face when you sit the exam. In short, the course covers the following areas:
- Foundatiuons of cyber threat intelligence
- Intelligence lifecycle
- Obtaining intelligence requirements to generate requests for information
- Data, Information, Intelligence
- Cyber Kill Chain, Mitre ATT&CK framework
- Systems thinking
- Analytical reasoning, including processes like analysis of competing hypothesis (ACH)
- Basics of cybersecurity as it relates to the CTI specialism (malware, kill chains, common exploits)
What does this exam actually preapre you for?
The exam itself preapres you to step into a role as an associate to mid level cyber threat intelligence analyst on a non-technical intelligence team. It probably warrants a little explainining what I mean by a non-technical intelligence analyst.
Lets assume your standard intelligence team looks like this…
Now most large organisations, including banks will have a team setup like this. The below list gives you an idea on what the exam will prepare you for. Anything marked with a ❌ means you’d need significant skills develpment outside of CPTIA’s syllabus to secure a role in that area. Anything marked with a ✅ means that the skills from the ArcX course, exam, and 1-2 years of industry experience wouls stand you in good stead into walking/pivoting laterally into the role.
- Technical intelligence analysts ❌
- Malware analysts and reverse engineers
- Technical intelligence analysts (Analysing logs, defense through deception, threat intel engineering)
- Dark Web & Cyber Underground ❌
- Dark web intelligence analysts
- Ransomware experts (negotatiors, reverse engineers)
- human intelligence (HUMINT) analysts (engaging with threat actors using personas to gather intelligence)
- web3 (cryptocurrency theft tinvestigation)
- Tactical Intellgence ✅
- CTI analysts (Reviewing threat reports, intelligence analysis)
- Strategic Intelligence ✅
- Strategic Intelligence Analyst
- Intelligence Manager
A quick note about strategic intelligence, the ✅ assumes that you’d already have leadership experience and have worked with cyber teams for considerable time, as you’d need a good business head and a good udnerstanding on how to lead a team, where CPTIA just gives you that context and understadning on what your team is working on. Having said that, CREST does have a Threat Intelligence Manager certification which assesses your capability to lead a team of intelligence experts ranging from technical analysts, geopolitics experts, through to dark web analysts.
Closing
Overall, you’ll find the exam isn’t very technical, and involves a lot of critical thinking and reasoning skills combined with some knowledge and buzzword regurgitation. It’ll prepare you nicely to step into an associate or mid level, non specialised CTI analyst role. If you wanted to do dark web, malware, geopolitics, or one of the other specialisms, you’d need to puruse additional training on top of what ArcX offers or what the exam assesses for.
The statement from CREST themselves says that the exam will preapre you to work as a threat intelligence analyst under a CREST qualified senior analyst, and they under a CREST qualified threat intelligence manager - and fucntions as a good ballbark for how you should see this exam.



