
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 2Objective 2
Cyber Kill Chain and MITRE ATT&CK Frameworks CTIA Practice Questions (Page 11)
Part of the Cyber Threats and Attack Frameworks domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
14concepts
Questions 51–54
- 51
A threat intelligence team is profiling an advanced persistent threat group that has been observed using specific tools and techniques. They want to understand the group's known behaviors and associated software to anticipate future activity. Which ATT&CK component would be most useful for this analysis?
Select an answer first - 52
An attacker has successfully installed a backdoor on a compromised server. The backdoor is designed to periodically check in with an external server to receive commands. Which Cyber Kill Chain phase is the attacker operating in when the backdoor communicates with the external server?
Select an answer first - 53
What is the main goal of the actions on objectives phase?
Select an answer first - 54
Which activity is an example of passive reconnaissance?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CTIA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.