
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 7Objective 1
Threat Hunting and Detection CTIA Practice Questions (Page 11)
Part of the Threat Hunting and Operational Integration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 51–52
- 51
A threat hunter has identified a compromised host that is beaconing to a known command-and-control (C2) server. The hunter has confirmed the activity and has evidence. The incident response team is currently handling a separate, more critical incident and cannot immediately respond to this new finding. The hunter's manager wants to ensure the finding is not lost and that the host is eventually remediated. What should the hunter do?
Select an answer first - 52
Which threat hunting methodology relies on known indicators of compromise (IOCs) to search for threats?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CTIA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.