
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 2Objective 1
Cyber Threats and Advanced Persistent Threats CTIA Practice Questions (Page 9)
Part of the Cyber Threats and Attack Frameworks domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 41–45
- 41
A security operations center is reviewing alerts for a potential APT. The following indicators have been observed: (1) a new user account created in a privileged group, (2) unusual PowerShell activity on a server, (3) outbound connections to a domain that is only 24 hours old, and (4) a file hash matching a known malware sample. Which combination of indicators is most indicative of an APT?
Select an answer first - 42
A security team is analyzing a breach where the attacker maintained access to a network for over a year, moving slowly between systems and using encrypted communications. The attacker's objective appeared to be continuous collection of intellectual property rather than immediate financial gain. Which characteristic is most definitive in classifying this as an APT?
Select an answer first - 43
Which of the following is a potential financial impact of a cyber threat on an organization?
Select an answer first - 44
An analyst is documenting an APT attack and notes the following sequence: the attacker researched employees on LinkedIn, sent a targeted email with a malicious attachment, the attachment exploited a vulnerability, the attacker installed a backdoor, and then moved to other systems. Which two stages of the Cyber Kill Chain are missing from this documentation?
Select an answer first - 45
A security team observes that an attacker is using spear-phishing emails that appear to come from the CEO, and when a user clicks the link, the attacker uses a remote access tool to control the machine. Which TTP is the attacker using for initial access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.