Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 1Objective 1

Introduction to Threat Intelligence CTIA Practice Questions (Page 4)

Part of the Threat Intelligence Fundamentals domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 2–3 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
12concepts

Questions 16–20

  1. 16foundation · easy

    Which stage of the threat intelligence lifecycle involves converting raw data into a format that can be analyzed?

    Select an answer first
  2. 17expert · hard

    A security team is evaluating threat intelligence sources. They have a limited budget but need high-confidence indicators for automated blocking. They are considering: (1) an open-source feed with many indicators but a high false-positive rate, (2) a commercial feed with high-confidence indicators but a significant cost, and (3) internal telemetry from past incidents. The team must minimize false positives while staying within budget. What is the best approach?

    Select an answer first
  3. 18application · medium

    A security analyst integrates multiple open-source threat intelligence feeds into the SIEM. Within a week, the SIEM generates thousands of alerts, most of which are false positives. The analyst is overwhelmed and cannot prioritize real threats. What is the most effective way to address this challenge?

    Select an answer first
  4. 19expert · hard

    A security analyst is mapping an advanced persistent threat (APT) campaign to the Cyber Kill Chain. The analyst has identified that the attacker delivered a weaponized document via email and is now establishing command-and-control (C2) communication. The analyst wants to use this mapping to improve detection. Which two stages of the Cyber Kill Chain are directly relevant to these observations?

    Select an answer first
  5. 20expert · hard

    A threat intelligence platform (TIP) needs to exchange data with external partners. Some partners use STIX/TAXII, while others use a proprietary API. The team wants to minimize integration effort while maintaining flexibility. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.