
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 2Objective 2
Cyber Kill Chain and MITRE ATT&CK Frameworks CTIA Practice Questions (Page 3)
Part of the Cyber Threats and Attack Frameworks domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
14concepts
Questions 11–15
- 11
An analyst is mapping an intrusion to MITRE ATT&CK. The attacker used a spearphishing email to deliver a malicious attachment, which then executed and downloaded additional tools. Which ATT&CK tactic best describes the initial delivery and execution of the attachment?
Select an answer first - 12
Which ATT&CK tactic corresponds to the Cyber Kill Chain's 'Exploitation' phase?
Select an answer first - 13
A user receives an email with a malicious attachment. When the user opens the attachment, the document exploits a vulnerability in the application to execute a payload. Which Cyber Kill Chain phase is being executed at the moment the payload runs?
Select an answer first - 14
How does ATT&CK's software category support threat intelligence?
Select an answer first - 15
In the MITRE ATT&CK framework, what does TTP stand for?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.