
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 7Objective 1
Threat Hunting and Detection CTIA Practice Questions (Page 6)
Part of the Threat Hunting and Operational Integration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 26–30
- 26
A small security team has limited staff and needs to continuously monitor for known indicators of compromise across thousands of endpoints. They also want to reduce alert fatigue. Which approach best balances automation and human oversight?
Select an answer first - 27
A company wants to establish a sustainable threat hunting program. They have a small security team and limited budget. Which element is most important to include in the program's initial design?
Select an answer first - 28
What is the primary difference between manual and automated threat hunting?
Select an answer first - 29
Which of the following is an example of a detection rule?
Select an answer first - 30
A company is establishing a threat hunting program and wants to measure its effectiveness. They have defined metrics such as number of hunts completed, time to detect, and number of findings validated. However, they are struggling to show the business value of the program to executives. Which metric or approach would BEST demonstrate the value of threat hunting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.