Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 4Objective 2

Data Processing and Exploitation CTIA Practice Questions (Page 11)

Part of the Data Collection and Processing domain, which makes up ~29% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
10concepts

Questions 51–54

  1. 51expert · hard

    A threat intelligence platform ingests indicators from an open-source feed that has a high false-positive rate. The feed provides IP addresses and domains, but some indicators are outdated or incorrectly categorized. The analyst must use this data to block malicious traffic, but blocking false positives could disrupt legitimate business operations. The analyst has access to commercial threat intelligence feeds and internal telemetry. What is the best approach to ensure the indicators are trustworthy before blocking?

    Select an answer first
  2. 52expert · hard

    A threat intelligence team is building a repository of indicators. The team has a limited budget for external data enrichment services. The team needs to prioritize which indicators to enrich first. The indicators include IP addresses, domains, and file hashes. Which indicators should the team enrich first to maximize the value of the enrichment budget?

    Select an answer first
  3. 53foundation · easy

    A threat intelligence analyst creates a graph showing the relationships between malicious domains, IP addresses, and malware hashes to present to management. This graphical representation is an example of:

    Select an answer first
  4. 54application · medium

    A threat intelligence analyst has correlated data from endpoint logs, network flows, and threat feeds to identify a pattern of lateral movement. The analyst needs to communicate the attack path to the incident response team in a way that highlights the sequence of compromised hosts and the tools used. What should the analyst do?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CTIA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.