
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 6Objective 1
Intelligence Reporting CTIA Practice Questions (Page 1)
Part of the Intelligence Reporting and Dissemination domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 1–5
- 1
A managed security service provider (MSSP) produces a threat intelligence report about a campaign targeting its clients in the healthcare sector. The report contains sensitive information about the campaign's TTPs and IOCs. The MSSP wants to share the report with its clients and also with a national health-sector information sharing and analysis center (ISAC). Which dissemination consideration is most important?
Select an answer first - 2
A threat intelligence team has drafted a report on a zero-day vulnerability affecting a widely used email gateway. The report contains technical details, IOCs, and recommended mitigations. The team is about to disseminate the report to system administrators and executives. Which step is most important to complete before dissemination?
Select an answer first - 3
A threat intelligence analyst is preparing a report on a sophisticated supply chain attack that has affected several organizations in the same sector. The analyst's organization is a potential target, but there is no direct evidence of compromise. The report will be shared with the organization's executive leadership and the information sharing and analysis center (ISAC) for the sector. The analyst must balance the need for timely warning with the risk of causing unnecessary alarm. What is the most appropriate approach?
Select an answer first - 4
Why is it important to have a formal approval step before disseminating an intelligence report?
Select an answer first - 5
A threat intelligence analyst at a financial institution has completed a detailed analysis of a new banking trojan campaign targeting the organization's customers. The analyst must now produce a report for two audiences: the executive board, who need to understand the business impact and risk, and the security operations center (SOC) analysts, who will use the technical indicators to hunt for the threat. What is the most appropriate approach for the analyst to take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.