Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 6Objective 2

Dissemination of Threat Intelligence CTIA Practice Questions (Page 5)

Part of the Intelligence Reporting and Dissemination domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 21–25

  1. 21foundation · easy

    Which of the following is an example of an automated dissemination channel for threat intelligence?

    Select an answer first
  2. 22expert · medium

    A threat intelligence team at a large enterprise has been disseminating a monthly intelligence report to the security operations center (SOC) and the incident response (IR) team. The SOC team has provided feedback that the report is too long and the indicators are not prioritized, while the IR team has complained that the report often arrives after an incident has already occurred. The team has limited resources and cannot produce multiple versions of the report. What should the team do to address both concerns?

    Select an answer first
  3. 23application · medium

    A threat intelligence analyst needs to provide real-time updates on emerging threats to a geographically dispersed security team. The team members work in different time zones and need to access the information at any time. Which dissemination channel is most appropriate?

    Select an answer first
  4. 24application · medium

    A threat intelligence team wants to share structured threat intelligence with external partners using a standardized format that supports the full range of threat information, including indicators, TTPs, and campaign context. Which format should they choose?

    Select an answer first
  5. 25application · medium

    A threat intelligence platform (TIP) needs to automatically share indicators of compromise (IOCs) with partner organizations' security tools. The sharing must be machine-readable, support real-time updates, and follow a widely adopted standard. Which combination of format and transport should the analyst choose?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.