Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 5Objective 1

Data Analysis Techniques CTIA Practice Questions (Page 10)

Part of the Data Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)

58questions here
12free pages
13concepts

Questions 46–50

  1. 46application · medium

    An analyst is examining the frequency of a specific malware signature in network traffic over the past 30 days. The analyst wants to determine whether the daily count of detections is unusually high on a particular day. Which statistical method is most appropriate?

    Select an answer first
  2. 47application · medium

    A threat intelligence team is preparing a report for the board. They have two types of data: (1) a survey of security analysts' opinions about the most likely next attack vector, and (2) the actual number of phishing emails blocked per month. The team wants to present both types of data appropriately. Which statement correctly distinguishes the two types of analysis?

    Select an answer first
  3. 48expert · hard

    An analyst is correlating data from network logs, endpoint detection, and threat intelligence feeds to identify a potential advanced persistent threat (APT). The network logs show a series of outbound connections to a low-reputation IP, but the endpoint logs show no signs of compromise. The threat feed flags the IP as a known C2 server. What is the most appropriate conclusion?

    Select an answer first
  4. 49expert · hard

    An analyst has a malware sample that is packed and obfuscated. Static analysis reveals very little because the strings are encrypted and the imports are hidden. The analyst needs to understand the malware's behavior, but the sandbox environment is unable to execute the sample because it detects the sandbox and exits. Which combination of techniques is most appropriate to overcome this challenge?

    Select an answer first
  5. 50expert · hard

    A threat intelligence team needs to present a year-long analysis of phishing campaigns to the board. The data includes the number of phishing emails per month, the industries targeted, and the malware families used. The board is most interested in the overall trend and the shift in targeted industries. Which visualization approach would best communicate this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.