
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 2Objective 1
Cyber Threats and Advanced Persistent Threats CTIA Practice Questions (Page 7)
Part of the Cyber Threats and Attack Frameworks domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 31–35
- 31
A company's website is flooded with traffic from many compromised devices, causing it to become unavailable. The company also discovers that a malicious attachment in an email has infected several computers with spyware. Which two types of cyber threats are demonstrated?
Select an answer first - 32
Which of the following is a common TTP used by APT groups to gain an initial foothold?
Select an answer first - 33
A threat intelligence analyst is profiling an APT group that uses spear-phishing with malicious macros, then employs PowerShell to download additional tools, and finally uses SMB for lateral movement. The analyst wants to create detection signatures that are resilient to changes in the group's tools but focus on their behavior. Which approach is most effective?
Select an answer first - 34
Which TTP involves an attacker moving from one compromised system to another within a network?
Select an answer first - 35
A security analyst is investigating a data breach at a non-profit organization that advocates for environmental protection. The breach involved defacement of the website and release of internal emails. The attacker did not demand money and did not appear to be state-sponsored. Which threat actor type and motivation best fit this scenario?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.