Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 4Objective 2

Data Processing and Exploitation CTIA Practice Questions (Page 1)

Part of the Data Collection and Processing domain, which makes up ~29% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
10concepts

Questions 1–5

  1. 1application · medium

    A threat intelligence analyst has collected a large dataset of indicators from an automated feed. The analyst notices that many indicators are duplicates or have incomplete fields, such as missing hashes. Before using this data for a report, what should the analyst do?

    Select an answer first
  2. 2expert · hard

    A threat intelligence team must present a comprehensive view of a multi-stage attack to both technical and non-technical stakeholders. The technical team needs detailed indicators and correlation data, while executives need a high-level summary of impact and risk. The team has limited time to prepare the presentation. What is the most effective way to communicate the intelligence?

    Select an answer first
  3. 3foundation · easy

    In the threat intelligence data processing pipeline, which stage is primarily responsible for converting raw data from its original format into a consistent, structured representation that can be used by downstream analysis tools?

    Select an answer first
  4. 4application · medium

    A junior analyst is tasked with processing raw threat data from various sources. The analyst asks what the first step should be after collecting the data. Based on the data processing lifecycle, what should the analyst do?

    Select an answer first
  5. 5foundation · easy

    A threat intelligence platform receives IP addresses from firewall logs, domain names from DNS logs, and file hashes from antivirus reports. To correlate these indicators across the platform, what must be done first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.