
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 5Objective 1
Data Analysis Techniques CTIA Practice Questions (Page 3)
Part of the Data Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
13concepts
Questions 11–15
- 11
What is the primary purpose of data correlation in threat intelligence?
Select an answer first - 12
A CTI analyst is preparing a report on a new APT group. The analyst has collected data on the group's TTPs, victimology, and the malware they use. The analyst wants to include both quantitative and qualitative analysis in the report. Which combination best represents this approach?
Select an answer first - 13
Which type of data is most relevant for spatial analysis?
Select an answer first - 14
A security analyst is correlating a suspicious IP address from firewall logs with threat intelligence feeds. The IP is flagged by one feed as a known C2 server, but another feed lists it as a legitimate content delivery network. The analyst also finds that the IP has a historical relationship with several malware samples. What should the analyst do to make the most informed decision?
Select an answer first - 15
A security analyst has extracted a list of IP addresses from a malware sample's configuration file. The analyst wants to determine which of these IPs are known command-and-control (C2) servers. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.