Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 7Objective 1

Threat Hunting and Detection CTIA Practice Questions (Page 10)

Part of the Threat Hunting and Operational Integration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
10concepts

Questions 46–50

  1. 46foundation · easy

    What is a key advantage of hypothesis-driven threat hunting over IOC-based hunting?

    Select an answer first
  2. 47expert · hard

    A security team has developed a new detection rule for a specific malware family. During validation, they find that the rule has a high true positive rate but also a high false positive rate. The team is concerned about alert fatigue but does not want to miss any real infections. They have a limited number of analysts. Which strategy would BEST balance the need to detect the malware while minimizing false positives?

    Select an answer first
  3. 48application · medium

    A security operations center (SOC) is investigating a potential lateral movement attack. They need to identify which internal hosts communicated with a known malicious IP address over the past 48 hours. Which combination of data sources would provide the most complete evidence?

    Select an answer first
  4. 49foundation · easy

    What is the primary purpose of threat hunting in a cybersecurity defense program?

    Select an answer first
  5. 50expert · hard

    A threat hunter is working on a hypothesis that an attacker is using scheduled tasks to maintain persistence on Windows servers. The hunter has collected data from multiple sources, including Windows Event Logs, Sysmon, and threat intelligence feeds. After analyzing the data, the hunter finds several scheduled tasks that were created recently, but none of them match known malicious indicators. What should the hunter do NEXT?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.