Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 1Objective 1

Introduction to Threat Intelligence CTIA Practice Questions (Page 6)

Part of the Threat Intelligence Fundamentals domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 2–3 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
12concepts

Questions 26–30

  1. 26application · medium

    A small security team wants to enrich its threat detection with external indicators but has a limited budget and no dedicated threat intelligence platform. They need a source that is freely accessible, provides a wide range of indicators, and can be integrated into their existing SIEM via a standard protocol. Which approach best meets these constraints?

    Select an answer first
  2. 27application · medium

    A threat intelligence analyst is tasked with building a new intelligence capability. The analyst has gathered requirements from stakeholders, identified relevant sources, and started collecting data. According to the threat intelligence lifecycle, what should the analyst do next?

    Select an answer first
  3. 28application · medium

    A mid-sized e-commerce company wants to prioritize its security investments for the next fiscal year. The security team has collected threat data from multiple sources but lacks a clear process to turn it into actionable insights for management. Which primary goal of threat intelligence should the team focus on to address this gap?

    Select an answer first
  4. 29expert · hard

    A multinational corporation is establishing a threat intelligence program. The SOC requires tactical intelligence for daily alert triage, while the executive team needs strategic intelligence for risk reporting. The program has limited staff and must avoid overwhelming analysts with false positives. The team plans to use open-source feeds and internal telemetry. Which lifecycle approach best balances these competing needs?

    Select an answer first
  5. 30foundation · easy

    How do false positives affect threat intelligence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.