
EC-Council Certified Threat Intelligence Analyst (CTIA)
The EC-Council Certified Threat Intelligence Analyst (CTIA) certification validates your ability to collect, analyze, and disseminate cyber threat intelligence that helps organizations predict and prevent attacks. Designed for security professionals involved in threat intelligence operations, the program covers the full intelligence lifecycle—from planning and direction to analysis and dissemination. Earning CTIA demonstrates you can turn raw threat data into actionable intelligence that strengthens organizational defense.
800 practice questions · Updated 2026-07-30
CTIA Curriculum
Every domain, objective, and concept the CTIA exam measures.
- Definition of Threat Intelligence
- Threat Intelligence vs. Threat Data vs. Threat Information
- Goals of Threat Intelligence
- Threat Intelligence Users and Use Cases
- Threat Intelligence Lifecycle
- Strategic, Tactical, Operational, and Technical Intelligence
- Threat Intelligence Sources
- Threat Intelligence Feeds and APIs
- Indicators of Compromise (IoCs)
- Threat Intelligence Sharing and Communities
- Challenges in Threat Intelligence
- Threat Intelligence Standards and Frameworks
- Definition of Threat Intelligence
- Strategic Threat Intelligence
- Operational Threat Intelligence
- Tactical Threat Intelligence
- Technical Threat Intelligence
- Comparison of Intelligence Types
- Definition of Cyber Threats
- Threat Actors and Motivations
- Threat Vectors and Attack Surfaces
- Advanced Persistent Threats (APTs) Characteristics
- APT Lifecycle and Kill Chain
- APT Tactics, Techniques, and Procedures (TTPs)
- Indicators of Compromise (IoCs) for APTs
- Impact of Cyber Threats on Organizations
- Cyber Kill Chain Overview
- Reconnaissance Phase
- Weaponization Phase
- Delivery Phase
- Exploitation Phase
- Installation Phase
- Command and Control (C2) Phase
- Actions on Objectives Phase
- MITRE ATT&CK Framework Overview
- ATT&CK Tactics
- ATT&CK Techniques and Sub-techniques
- ATT&CK Groups and Software
- Mapping Cyber Kill Chain to ATT&CK
- Applying Frameworks in Threat Intelligence
- Threat Intelligence Program Definition
- Program Goals and Objectives
- Stakeholder Identification
- Requirements Gathering
- Intelligence Requirements Prioritization
- Program Scope and Charter
- Resource Planning
- Team Structure and Roles
- Tool and Technology Selection
- Process and Workflow Design
- Metrics and Performance Measurement
- Reporting and Communication Plan
- Legal and Ethical Considerations
- Budget and Cost Management
- Risk Management Integration
- Continuous Improvement
- Threat Intelligence Program Direction
- Review Process for Threat Intelligence
- Stakeholder Engagement
- Continuous Improvement
- Threat Intelligence Data Collection Overview
- Data Collection Planning
- Automated Data Collection Tools
- Manual Data Collection Techniques
- Data Source Validation
- Data Collection from Open Sources
- Data Collection from Technical Sources
- Data Collection from Human Sources
- Data Collection from Internal Sources
- Data Collection from External Sources
- Data Collection from Dark Web and Deep Web
- Data Collection from Social Media and Forums
- Data Collection from Malware Analysis
- Data Collection from Network Traffic
- Data Collection from Logs and Events
- Data Collection from Threat Intelligence Platforms
- Data Collection from Honeypots and Honeynets
- Data Collection from Sandboxing
- Data Collection from OSINT Tools
- Data Collection from HUMINT
- Data Collection from SIGINT
- Data Collection from Cyber Threat Intelligence Feeds
- Data Collection from Government and Law Enforcement Sources
- Data Collection from Industry-Specific Sources
- Data Collection from Academic and Research Sources
- Data Collection from Vulnerability Databases
- Data Collection from Incident Response Reports
- Data Collection from Threat Actor Communication
- Data Collection from Geolocation and IP Intelligence
- Data Collection from DNS and Domain Intelligence
- Data Collection from File and Hash Intelligence
- Data Collection from Email and Phishing Analysis
- Data Collection from Web and URL Analysis
- Data Collection from Social Engineering Intelligence
- Data Collection from Physical Security Sources
- Data Collection from Supply Chain Sources
- Data Collection from Insider Threat Sources
- Data Collection from Threat Modeling
- Data Collection from Cyber Kill Chain and MITRE ATT&CK
- Data Collection from Threat Hunting
- Data Collection from Deception Technologies
- Data Collection from Cloud and Virtual Environments
- Data Collection from IoT and OT Sources
- Data Collection from Mobile and Endpoint Sources
- Data Collection from Application and Database Logs
- Data Collection from Authentication and Access Logs
- Data Collection from Firewall and IDS/IPS Logs
- Data Collection from Proxy and Web Filter Logs
- Data Collection from Email Gateway Logs
- Data Collection from Endpoint Detection and Response (EDR)
- Data Collection from Security Information and Event Management (SIEM)
- Data Collection from Threat Intelligence Sharing Platforms
- Data Collection from Legal and Regulatory Sources
- Data Collection from Ethical and Privacy Considerations
- Data Collection from Data Quality and Relevance
- Data Collection from Data Normalization and Standardization
- Data Collection from Data Storage and Management
- Data Collection from Data Retention and Disposal
- Data Collection from Automation and Orchestration
- Data Collection from Integration with Existing Security Tools
- Data Collection from Continuous Monitoring
- Data Collection from Feedback and Improvement
- Data Processing Fundamentals
- Data Normalization
- Data Correlation
- Data Enrichment
- Data Aggregation
- Data Filtering and Reduction
- Data Validation and Quality Assurance
- Data Exploitation Techniques
- Data Visualization
- Data Storage and Management
- Data Analysis Techniques Overview
- Data Analysis Process
- Types of Data Analysis
- Statistical Analysis
- Temporal Analysis
- Spatial Analysis
- Relationship Analysis
- Malware Analysis Techniques
- Indicators of Compromise (IoC) Analysis
- Data Correlation
- Data Visualization
- Analytical Tools and Platforms
- Challenges in Data Analysis
- Threat Intelligence Evaluation Criteria
- Threat Intelligence Scoring and Prioritization
- Threat Intelligence Validation and Verification
- Threat Intelligence Runbook Purpose and Structure
- Runbook Development Process
- Runbook Integration and Maintenance
- Intelligence report purpose and audience
- Intelligence report structure and format
- Intelligence report writing standards
- Intelligence report review and approval
- Intelligence report dissemination
- Threat Intelligence Dissemination Overview
- Dissemination Methods and Channels
- Audience Identification and Tailoring
- Dissemination Formats and Standards
- Timeliness and Relevance in Dissemination
- Feedback and Iterative Improvement
- Threat Hunting Fundamentals
- Threat Hunting Process
- Threat Hunting Methodologies
- Threat Hunting Data Sources
- Threat Hunting Techniques
- Threat Hunting Tools
- Detection Engineering
- Detection Validation and Testing
- Integration with Incident Response
- Operationalizing Threat Hunting
- SOC Integration of Threat Intelligence
- Threat Intelligence in Incident Response
- Risk Management with Threat Intelligence
- Intelligence-Driven SOC Workflows
- Operationalizing Threat Intelligence
- Threat Intelligence for Incident Triage
- Threat Intelligence for Threat Hunting
- Threat Intelligence in Risk Scoring
- Collaboration Between SOC, IR, and Risk Teams
- Metrics for Intelligence-Driven Operations
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CTIA, so none is invented.