Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 2Objective 1

Cyber Threats and Advanced Persistent Threats CTIA Practice Questions (Page 3)

Part of the Cyber Threats and Attack Frameworks domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
8concepts

Questions 11–15

  1. 11foundation · easy

    Which of the following is an example of a technical indicator of compromise (IoC) for an APT?

    Select an answer first
  2. 12expert · hard

    An incident responder is analyzing a breach where the attacker gained access through a phishing email, then used a legitimate remote administration tool to move to the domain controller, and finally exfiltrated data via DNS queries. The responder needs to identify the earliest stage where detection could have occurred to minimize damage. Which stage of the Cyber Kill Chain should the responder focus on to prevent the attack from progressing?

    Select an answer first
  3. 13application · medium

    A mid-sized financial services firm has been experiencing a series of targeted phishing emails that contain no malware but ask employees to click links that lead to fake login pages. The emails are personalized with job titles and recent projects. The firm's leadership wants to understand the most likely threat actor and their primary motivation to guide defensive priorities. Which assessment is most accurate?

    Select an answer first
  4. 14application · medium

    A hospital experiences a ransomware attack that encrypts patient records and disrupts its appointment system for three days. The hospital's reputation suffers, and it faces regulatory fines. Which impact category is most directly illustrated by the disruption of the appointment system?

    Select an answer first
  5. 15expert · hard

    An incident response team is mapping an APT attack to the Cyber Kill Chain. They have identified the following events: (1) an attacker scanned the network for open ports, (2) sent a spear-phishing email with a malicious link, (3) exploited a browser vulnerability, (4) installed a backdoor, (5) established C2, and (6) exfiltrated data. Which stage is missing from this mapping?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.