Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 6Objective 1

Intelligence Reporting CTIA Practice Questions (Page 8)

Part of the Intelligence Reporting and Dissemination domain, which makes up ~10% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
5concepts

Questions 36–39

  1. 36application · medium

    A threat intelligence analyst at a university is preparing a report on a phishing campaign that targeted student email accounts. The report will be shared with the university's IT help desk, the dean of students, and the campus security office. Which report format is most appropriate for this mixed audience?

    Select an answer first
  2. 37application · medium

    A threat intelligence team has completed a draft report on a ransomware group's new tactics, techniques, and procedures (TTPs). The report contains sensitive information about the organization's vulnerabilities and will be shared with a limited group of stakeholders. According to the review and approval process, what should the team do before disseminating the report?

    Select an answer first
  3. 38expert · hard

    An analyst is writing a threat intelligence report on a nation-state actor's activities. The report will be reviewed by a senior analyst and then disseminated to the organization's executive leadership and a government partner. The analyst has information from a confidential source that is not yet fully corroborated. The analyst must decide how to present this information in the report. What is the most appropriate approach?

    Select an answer first
  4. 39application · medium

    An analyst is writing a threat intelligence report on a new exploit kit. The report will be shared with the organization's security operations center (SOC) and management. Which of the following elements should be included in the report to ensure it is complete and useful?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CTIA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.