
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 6Objective 1
Intelligence Reporting CTIA Practice Questions (Page 4)
Part of the Intelligence Reporting and Dissemination domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 16–20
- 16
A threat intelligence analyst is preparing a report on a new malware family that is being used in targeted attacks against the organization's industry. The report will be shared with the organization's SOC, the executive leadership, and a partner organization. The analyst must ensure that the report is structured to meet the needs of all three audiences. Which of the following structures is most appropriate?
Select an answer first - 17
A threat intelligence analyst has drafted a report on a new ransomware strain that is actively targeting the organization's industry. The report contains sensitive information about the organization's network architecture and a zero-day vulnerability that the ransomware exploits. The report is scheduled for dissemination to the incident response team and the executive leadership. During the review process, the legal department raises concerns about the inclusion of the zero-day vulnerability details, as it may increase the organization's liability if the report is leaked. The analyst must decide how to proceed. What is the best course of action?
Select an answer first - 18
A threat intelligence team has produced a report on a zero-day exploit that is being used in the wild. The report contains IOCs and mitigation steps. The team wants to share the report with its customers, but the report also contains information about a vulnerability in a third-party product that is not yet patched. The third-party vendor has asked the team not to disclose the vulnerability details publicly. What is the best dissemination strategy?
Select an answer first - 19
A threat intelligence analyst has completed a draft report on a supply-chain attack that affected the company's third-party software vendor. The report includes technical details, impact assessment, and recommended actions. The analyst's supervisor is out of the office for two weeks. What is the best course of action to ensure the report is reviewed and approved in a timely manner?
Select an answer first - 20
Which step is typically part of the review and approval process for an intelligence report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.