
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 6Objective 2
Dissemination of Threat Intelligence CTIA Practice Questions (Page 3)
Part of the Intelligence Reporting and Dissemination domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 11–15
- 11
During a fast-moving ransomware campaign, a threat intelligence analyst has confirmed new indicators and updated TTPs. The SOC needs to block the indicators immediately, while the incident response team needs the updated TTPs to contain the spread. What is the most appropriate dissemination action?
Select an answer first - 12
A threat intelligence team at a government agency has been disseminating intelligence products to various internal teams, including the SOC, the threat hunting team, and the executive leadership. The SOC has provided feedback that the indicators are often outdated by the time they receive them, while the threat hunting team has complained that the reports lack sufficient context for proactive hunting. The executive leadership has not provided any feedback. The team has limited resources and cannot produce multiple versions of each product. What should the team do to address the feedback?
Select an answer first - 13
A threat intelligence analyst at a multinational corporation has produced a report on a new ransomware campaign targeting the company's subsidiaries in different regions. The report includes technical indicators, a detailed analysis of the ransomware's behavior, and an assessment of the potential impact on each region. The analyst must share this with the regional IT security teams, the global CISO, and the regional legal counsels. The regional teams have different technical capabilities and regulatory requirements. What is the most effective dissemination strategy?
Select an answer first - 14
What does 'relevance' mean in the context of threat intelligence dissemination?
Select an answer first - 15
A threat intelligence analyst at a financial institution has identified a new phishing kit that is being used to target the institution's customers. The analyst has created a detailed analysis report, but the report is scheduled to be published in the weekly intelligence bulletin, which is three days away. The SOC has requested the indicators immediately to update their blocklists. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.