Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 4Objective 2

Data Processing and Exploitation CTIA Practice Questions (Page 6)

Part of the Data Collection and Processing domain, which makes up ~29% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 8–12 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
10concepts

Questions 26–30

  1. 26expert · hard

    A security team is integrating a new threat intelligence feed into its SIEM. The feed provides indicators in a proprietary format that does not match the SIEM's schema. The team must ensure that the indicators are correctly mapped and that no data is lost during ingestion. What is the most important step?

    Select an answer first
  2. 27application · medium

    A threat intelligence team needs to present the geographic distribution of attack sources and the timeline of a multi-stage campaign to non-technical executives. Which approach best communicates this processed data?

    Select an answer first
  3. 28foundation · easy

    During threat intelligence analysis, an analyst notices that the same IP address appears in firewall logs, a phishing email header, and a malware sandbox report. What process is being used to identify this relationship?

    Select an answer first
  4. 29foundation · easy

    Which of the following best describes the overall purpose of the data processing stage in threat intelligence?

    Select an answer first
  5. 30expert · hard

    A security operations center is investigating a potential data exfiltration. The analyst has access to firewall logs, DNS logs, and endpoint logs. The firewall logs show a large outbound transfer to an external IP, but the DNS logs do not show any domain resolution for that IP. The endpoint logs show a process that has not been seen before. The analyst needs to determine if the transfer is malicious. What should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.