
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 6Objective 2
Dissemination of Threat Intelligence CTIA Practice Questions (Page 7)
Part of the Intelligence Reporting and Dissemination domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 31–35
- 31
A CTI team has been disseminating threat intelligence via a weekly email digest. The SOC has complained that the digest is often outdated by the time it arrives, and they miss critical indicators. The team wants to improve timeliness without overwhelming the SOC with too many alerts. What is the best approach?
Select an answer first - 32
A CTI team has been producing weekly threat intelligence reports for the SOC. The SOC analysts have expressed that the reports are too long and they often miss the key actions they need to take. The team wants to improve the reports. What is the best way to address this feedback?
Select an answer first - 33
A threat intelligence team needs to disseminate a new set of indicators to a large number of internal security tools and also provide a human-readable summary for the security management team. The indicators must be updated automatically as new intelligence is received. Which dissemination method should the team use?
Select an answer first - 34
A threat intelligence analyst at a healthcare organization has developed a threat report on a ransomware group targeting the healthcare sector. The report contains technical indicators, a detailed analysis of the group's tactics, techniques, and procedures (TTPs), and an assessment of the potential impact on patient data. The analyst must share this with the IT security team, the hospital's legal counsel, and the public relations (PR) department. What is the most effective way to disseminate this intelligence?
Select an answer first - 35
A government agency needs to share threat intelligence with a trusted partner organization. The agency wants to ensure the intelligence is shared in a standardized, machine-readable format that supports the exchange of indicators and full reports. The partner uses a different threat intelligence platform (TIP). Which approach should the agency use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.