Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 7Objective 1

Threat Hunting and Detection CTIA Practice Questions (Page 1)

Part of the Threat Hunting and Operational Integration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 1–5

  1. 1application · medium

    A security analyst is new to threat hunting and wants to understand how it differs from traditional security monitoring. Which statement best describes the core difference?

    Select an answer first
  2. 2expert · hard

    A threat hunter is planning a hunt for credential dumping on Windows systems. The hunter has access to Sysmon logs, Windows Security logs, and network logs. The hunter wants to use a combination of data sources to detect both local and remote credential dumping. Which data source combination would be MOST effective?

    Select an answer first
  3. 3application · medium

    A small security team needs to start a threat hunting program but has limited budget and no dedicated hunting platform. They have access to Windows Event Logs, Sysmon, and a SIEM with basic query capabilities. They want to hunt for lateral movement using pass-the-hash techniques. Which tool or approach would be MOST practical for this team?

    Select an answer first
  4. 4application · medium

    A threat hunter is looking for signs of data exfiltration in a corporate network. The hunter has access to NetFlow data, proxy logs, and endpoint DLP alerts. Which combination of techniques would be MOST effective in identifying potential exfiltration?

    Select an answer first
  5. 5application · medium

    A security analyst at a mid-sized company is tasked with detecting a newly discovered malware family that uses a unique domain generation algorithm (DGA) and communicates over HTTPS with domains registered only hours before use. The analyst has access to DNS logs, proxy logs, and endpoint EDR telemetry. Which approach would be MOST effective for detecting this threat in the environment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.