
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 3Objective 2
Direction and Review of the Threat Intelligence Program CTIA Practice Questions (Page 5)
Part of the Requirements, Planning and Direction domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
4concepts
Questions 21–25
- 21
A large healthcare organization is reviewing its threat intelligence program. The program currently serves the security team and the compliance office. The organization is planning to launch a telemedicine service, which introduces new cyber risks and regulatory requirements. The CISO wants to ensure the program's direction supports this new service. Which stakeholder should be added to the program's review team to best inform the direction?
Select an answer first - 22
A government contractor is establishing a threat intelligence program. The organization's primary goal is to protect classified information systems from advanced persistent threats (APTs). The program's vision statement should reflect the desired future state. Which vision statement is most appropriate?
Select an answer first - 23
A threat intelligence program has been using the same set of KPIs for three years. The KPIs include the number of reports produced, the number of IOCs shared, and the number of briefings delivered. A review shows that these KPIs are all being met, but the program's overall effectiveness is questioned by senior leadership. The program manager must revise the KPIs. Which KPI set would best demonstrate the program's value to senior leadership?
Select an answer first - 24
A global bank's threat intelligence program has been running for two years. The program produces high-quality strategic reports that the board uses for risk decisions. However, the SOC team reports that the tactical indicators (IOCs) provided are often outdated by the time they are delivered, and the fraud team says the intelligence does not address financial crime patterns. The program manager must revise the program's KPIs. Which KPI set would best balance the needs of all three stakeholder groups?
Select an answer first - 25
A threat intelligence program's annual review reveals that the program's KPIs are not being met. The team identifies that the intelligence requirements are too broad and not prioritized. The program manager wants to use the review findings to improve the program. Which action best supports continuous improvement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.