
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 2Objective 2
Cyber Kill Chain and MITRE ATT&CK Frameworks CTIA Practice Questions (Page 8)
Part of the Cyber Threats and Attack Frameworks domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
14concepts
Questions 36–40
- 36
Which of the following is a common technique used in the weaponization phase?
Select an answer first - 37
Which ATT&CK tactic involves techniques for moving laterally within a network?
Select an answer first - 38
A threat intelligence team is analyzing a new malware sample and wants to determine if it is associated with a known threat group. They have identified several techniques used by the malware and want to compare them to known group behaviors. Which approach would be most effective?
Select an answer first - 39
An organization has strong email filtering and endpoint protection, but a recent intrusion succeeded because the attacker used a compromised vendor account to access a file share and then used PowerShell to download additional tools. Using the Cyber Kill Chain and ATT&CK, which gap in defenses is most evident?
Select an answer first - 40
In the weaponization phase, what do attackers typically create?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.