
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 2Objective 2
Cyber Kill Chain and MITRE ATT&CK Frameworks CTIA Practice Questions (Page 5)
Part of the Cyber Threats and Attack Frameworks domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
14concepts
Questions 21–25
- 21
A threat intelligence analyst is mapping an intrusion to both the Cyber Kill Chain and MITRE ATT&CK. The attacker used a public-facing web application vulnerability to gain initial access, then created a local user account, and later used that account to move laterally. The analyst needs to produce a mapping that best represents the attack lifecycle. Which mapping is most accurate?
Select an answer first - 22
Which ATT&CK tactic best maps to the Cyber Kill Chain's 'Command and Control' phase?
Select an answer first - 23
A security team wants to standardize how they describe adversary behaviors across different incidents. They need a framework that organizes behaviors into tactical objectives and provides specific, actionable descriptions of how those objectives are achieved. Which framework best meets this need?
Select an answer first - 24
In the exploitation phase, what occurs?
Select an answer first - 25
In MITRE ATT&CK, what is a 'Group'?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.