Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 4Objective 2

Data Processing and Exploitation CTIA Practice Questions (Page 3)

Part of the Data Collection and Processing domain, which makes up ~29% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
10concepts

Questions 11–15

  1. 11application · medium

    A security analyst is reviewing alerts from multiple sources: an IDS flagged a suspicious connection to an external IP, a proxy log shows a user visited a known malicious domain, and an endpoint log shows a new process running. The analyst suspects these events are related to a single intrusion. What should the analyst do to confirm the relationship?

    Select an answer first
  2. 12application · medium

    A threat intelligence analyst collects firewall logs (CSV), proxy logs (JSON), and DNS logs (key-value pairs) from different security tools. The analyst needs to correlate events across these sources to identify a coordinated attack. What should the analyst do first to enable effective correlation?

    Select an answer first
  3. 13application · medium

    An analyst has identified a suspicious domain that has been used in a phishing campaign. The domain is not in any internal threat feed. The analyst wants to add this domain to the threat intelligence platform with additional context to support future investigations. What should the analyst do?

    Select an answer first
  4. 14expert · hard

    An organization is investigating a potential data breach. The security team has collected logs from authentication servers, endpoint devices, and network proxies. The logs are in different formats and time zones. The team needs to identify the attack path and present it to management. The team has limited time and resources. What should the team do first to efficiently identify the attack path?

    Select an answer first
  5. 15foundation · easy

    What is the primary benefit of data normalization in threat intelligence processing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.