Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 5Objective 1

Data Analysis Techniques CTIA Practice Questions (Page 11)

Part of the Data Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)

58questions here
12free pages
13concepts

Questions 51–55

  1. 51foundation · easy

    What is the primary purpose of data visualization in threat intelligence?

    Select an answer first
  2. 52expert · hard

    A threat intelligence team is analyzing a malware campaign. They have the following data: a C2 domain that resolves to an IP address, a malware sample that connects to that domain, and a phishing email that delivered the sample. The team wants to produce a visual that clearly shows how these entities are connected and highlights the central node that ties the campaign together. Which visualization and analysis approach is most appropriate?

    Select an answer first
  3. 53application · medium

    An analyst is investigating a series of attacks that appear to originate from IP addresses in several countries. The analyst wants to determine if these attacks are coordinated or independent. What is the most effective first step?

    Select an answer first
  4. 54expert · hard

    A threat intelligence team is correlating data from multiple sources: a commercial threat feed, an open-source intelligence (OSINT) collection, and internal DNS logs. The commercial feed reports a specific domain as malicious, but the OSINT collection has no record of it, and the internal DNS logs show only one query to that domain from a single host. The team must decide whether to block the domain. Which consideration is most important when evaluating the correlation results?

    Select an answer first
  5. 55foundation · easy

    Which sequence correctly represents the typical steps in the threat intelligence data analysis process?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.