Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 4Objective 2

Data Processing and Exploitation CTIA Practice Questions (Page 4)

Part of the Data Collection and Processing domain, which makes up ~29% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
10concepts

Questions 16–20

  1. 16expert · hard

    An analyst has correlated multiple indicators and identified a potential phishing campaign targeting employees. The analyst has enriched the indicators with threat intelligence and filtered out false positives. The analyst must now decide which indicators to include in a blocklist for the email gateway. The blocklist has a limited capacity. What should the analyst prioritize?

    Select an answer first
  2. 17foundation · easy

    A threat intelligence team stores processed indicators in a centralized database that supports fast queries and allows other analysts to retrieve historical data. This practice is an example of:

    Select an answer first
  3. 18application · medium

    After processing a large dataset of indicators, an analyst notices that some indicators from an automated feed conflict with manually verified data. Before using this data in a report, what should the analyst do?

    Select an answer first
  4. 19expert · hard

    A threat intelligence analyst is evaluating a new commercial threat feed. The feed provides a high volume of indicators, but the analyst has found that some indicators are false positives. The analyst needs to decide whether to integrate the feed into the platform. The feed is the only source for a specific type of malware that is targeting the organization. What should the analyst do?

    Select an answer first
  5. 20application · medium

    A threat intelligence platform is ingesting millions of DNS queries daily. The analyst needs to identify only the queries that match known malicious domains or suspicious patterns, such as long subdomains or high query frequency. The platform's storage and processing capacity is limited. What should the analyst do to focus on actionable intelligence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.