Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-COUNCIL

EC-Council Certified Threat Intelligence Analyst (CTIA)

CTIACertified Threat Intelligence Analyst

The EC-Council Certified Threat Intelligence Analyst (CTIA) certification validates your ability to collect, analyze, and disseminate cyber threat intelligence that helps organizations predict and prevent attacks. Designed for security professionals involved in threat intelligence operations, the program covers the full intelligence lifecycle—from planning and direction to analysis and dissemination. Earning CTIA demonstrates you can turn raw threat data into actionable intelligence that strengthens organizational defense.

800 practice questions · Updated 2026-07-30

7Domains
14Objectives
182Concepts
800Questions

CTIA Curriculum

Every domain, objective, and concept the CTIA exam measures.

Introduction to Threat Intelligence

12 concepts · 42 questions
  1. Definition of Threat Intelligence
  2. Threat Intelligence vs. Threat Data vs. Threat Information
  3. Goals of Threat Intelligence
  4. Threat Intelligence Users and Use Cases
  5. Threat Intelligence Lifecycle
  6. Strategic, Tactical, Operational, and Technical Intelligence
  7. Threat Intelligence Sources
  8. Threat Intelligence Feeds and APIs
  9. Indicators of Compromise (IoCs)
  10. Threat Intelligence Sharing and Communities
  11. Challenges in Threat Intelligence
  12. Threat Intelligence Standards and Frameworks
  1. Definition of Threat Intelligence
  2. Strategic Threat Intelligence
  3. Operational Threat Intelligence
  4. Tactical Threat Intelligence
  5. Technical Threat Intelligence
  6. Comparison of Intelligence Types

  1. Definition of Cyber Threats
  2. Threat Actors and Motivations
  3. Threat Vectors and Attack Surfaces
  4. Advanced Persistent Threats (APTs) Characteristics
  5. APT Lifecycle and Kill Chain
  6. APT Tactics, Techniques, and Procedures (TTPs)
  7. Indicators of Compromise (IoCs) for APTs
  8. Impact of Cyber Threats on Organizations
  1. Cyber Kill Chain Overview
  2. Reconnaissance Phase
  3. Weaponization Phase
  4. Delivery Phase
  5. Exploitation Phase
  6. Installation Phase
  7. Command and Control (C2) Phase
  8. Actions on Objectives Phase
  9. MITRE ATT&CK Framework Overview
  10. ATT&CK Tactics
  11. ATT&CK Techniques and Sub-techniques
  12. ATT&CK Groups and Software
  13. Mapping Cyber Kill Chain to ATT&CK
  14. Applying Frameworks in Threat Intelligence

  1. Threat Intelligence Program Definition
  2. Program Goals and Objectives
  3. Stakeholder Identification
  4. Requirements Gathering
  5. Intelligence Requirements Prioritization
  6. Program Scope and Charter
  7. Resource Planning
  8. Team Structure and Roles
  9. Tool and Technology Selection
  10. Process and Workflow Design
  11. Metrics and Performance Measurement
  12. Reporting and Communication Plan
  13. Legal and Ethical Considerations
  14. Budget and Cost Management
  15. Risk Management Integration
  16. Continuous Improvement
  1. Threat Intelligence Program Direction
  2. Review Process for Threat Intelligence
  3. Stakeholder Engagement
  4. Continuous Improvement

Threat Intelligence Data Collection

62 concepts · 175 questions
  1. Threat Intelligence Data Collection Overview
  2. Data Collection Planning
  3. Automated Data Collection Tools
  4. Manual Data Collection Techniques
  5. Data Source Validation
  6. Data Collection from Open Sources
  7. Data Collection from Technical Sources
  8. Data Collection from Human Sources
  9. Data Collection from Internal Sources
  10. Data Collection from External Sources
  11. Data Collection from Dark Web and Deep Web
  12. Data Collection from Social Media and Forums
  13. Data Collection from Malware Analysis
  14. Data Collection from Network Traffic
  15. Data Collection from Logs and Events
  16. Data Collection from Threat Intelligence Platforms
  17. Data Collection from Honeypots and Honeynets
  18. Data Collection from Sandboxing
  19. Data Collection from OSINT Tools
  20. Data Collection from HUMINT
  21. Data Collection from SIGINT
  22. Data Collection from Cyber Threat Intelligence Feeds
  23. Data Collection from Government and Law Enforcement Sources
  24. Data Collection from Industry-Specific Sources
  25. Data Collection from Academic and Research Sources
  26. Data Collection from Vulnerability Databases
  27. Data Collection from Incident Response Reports
  28. Data Collection from Threat Actor Communication
  29. Data Collection from Geolocation and IP Intelligence
  30. Data Collection from DNS and Domain Intelligence
  31. Data Collection from File and Hash Intelligence
  32. Data Collection from Email and Phishing Analysis
  33. Data Collection from Web and URL Analysis
  34. Data Collection from Social Engineering Intelligence
  35. Data Collection from Physical Security Sources
  36. Data Collection from Supply Chain Sources
  37. Data Collection from Insider Threat Sources
  38. Data Collection from Threat Modeling
  39. Data Collection from Cyber Kill Chain and MITRE ATT&CK
  40. Data Collection from Threat Hunting
  41. Data Collection from Deception Technologies
  42. Data Collection from Cloud and Virtual Environments
  43. Data Collection from IoT and OT Sources
  44. Data Collection from Mobile and Endpoint Sources
  45. Data Collection from Application and Database Logs
  46. Data Collection from Authentication and Access Logs
  47. Data Collection from Firewall and IDS/IPS Logs
  48. Data Collection from Proxy and Web Filter Logs
  49. Data Collection from Email Gateway Logs
  50. Data Collection from Endpoint Detection and Response (EDR)
  51. Data Collection from Security Information and Event Management (SIEM)
  52. Data Collection from Threat Intelligence Sharing Platforms
  53. Data Collection from Legal and Regulatory Sources
  54. Data Collection from Ethical and Privacy Considerations
  55. Data Collection from Data Quality and Relevance
  56. Data Collection from Data Normalization and Standardization
  57. Data Collection from Data Storage and Management
  58. Data Collection from Data Retention and Disposal
  59. Data Collection from Automation and Orchestration
  60. Data Collection from Integration with Existing Security Tools
  61. Data Collection from Continuous Monitoring
  62. Data Collection from Feedback and Improvement

Data Processing and Exploitation

10 concepts · 54 questions
  1. Data Processing Fundamentals
  2. Data Normalization
  3. Data Correlation
  4. Data Enrichment
  5. Data Aggregation
  6. Data Filtering and Reduction
  7. Data Validation and Quality Assurance
  8. Data Exploitation Techniques
  9. Data Visualization
  10. Data Storage and Management

Data Analysis Techniques

13 concepts · 58 questions
  1. Data Analysis Techniques Overview
  2. Data Analysis Process
  3. Types of Data Analysis
  4. Statistical Analysis
  5. Temporal Analysis
  6. Spatial Analysis
  7. Relationship Analysis
  8. Malware Analysis Techniques
  9. Indicators of Compromise (IoC) Analysis
  10. Data Correlation
  11. Data Visualization
  12. Analytical Tools and Platforms
  13. Challenges in Data Analysis
  1. Threat Intelligence Evaluation Criteria
  2. Threat Intelligence Scoring and Prioritization
  3. Threat Intelligence Validation and Verification
  4. Threat Intelligence Runbook Purpose and Structure
  5. Runbook Development Process
  6. Runbook Integration and Maintenance

Intelligence Reporting

5 concepts · 39 questions
  1. Intelligence report purpose and audience
  2. Intelligence report structure and format
  3. Intelligence report writing standards
  4. Intelligence report review and approval
  5. Intelligence report dissemination

Dissemination of Threat Intelligence

6 concepts · 44 questions
  1. Threat Intelligence Dissemination Overview
  2. Dissemination Methods and Channels
  3. Audience Identification and Tailoring
  4. Dissemination Formats and Standards
  5. Timeliness and Relevance in Dissemination
  6. Feedback and Iterative Improvement

Threat Hunting and Detection

10 concepts · 52 questions
  1. Threat Hunting Fundamentals
  2. Threat Hunting Process
  3. Threat Hunting Methodologies
  4. Threat Hunting Data Sources
  5. Threat Hunting Techniques
  6. Threat Hunting Tools
  7. Detection Engineering
  8. Detection Validation and Testing
  9. Integration with Incident Response
  10. Operationalizing Threat Hunting
  1. SOC Integration of Threat Intelligence
  2. Threat Intelligence in Incident Response
  3. Risk Management with Threat Intelligence
  4. Intelligence-Driven SOC Workflows
  5. Operationalizing Threat Intelligence
  6. Threat Intelligence for Incident Triage
  7. Threat Intelligence for Threat Hunting
  8. Threat Intelligence in Risk Scoring
  9. Collaboration Between SOC, IR, and Risk Teams
  10. Metrics for Intelligence-Driven Operations
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CTIA, so none is invented.