
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 6Objective 1
Intelligence Reporting CTIA Practice Questions (Page 5)
Part of the Intelligence Reporting and Dissemination domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 21–25
- 21
What is a key consideration when disseminating an intelligence report to external stakeholders?
Select an answer first - 22
A threat intelligence analyst is writing a formal intelligence report on a newly identified Advanced Persistent Threat (APT) group. The report will be reviewed by a senior analyst and then disseminated to the organization's security leadership. Which of the following structures best conforms to standard intelligence reporting practices?
Select an answer first - 23
A threat intelligence analyst is writing a finished intelligence report on a phishing campaign that targeted the company's finance department. The analyst has confirmed the campaign's TTPs, identified the lure documents, and traced the infrastructure to a known threat group. The report must be reviewed by the CISO before dissemination. Which report structure best supports the review and approval process?
Select an answer first - 24
A threat intelligence analyst has completed a draft report on a new malware strain. The report is scheduled for dissemination to the organization's incident response team and system administrators. The analyst's supervisor is on leave, and the report is time-sensitive. What is the best course of action?
Select an answer first - 25
A threat intelligence analyst has produced a report on a zero-day vulnerability affecting the organization's internet-facing systems. The report includes technical details and indicators of compromise (IOCs). The analyst needs to disseminate this report to the IT security team and the executive leadership. What is the most appropriate dissemination method?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.