
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 7Objective 1
Threat Hunting and Detection CTIA Practice Questions (Page 7)
Part of the Threat Hunting and Operational Integration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 31–35
- 31
A threat hunter at a financial institution is investigating a hypothesis that attackers are using PowerShell to download and execute payloads from pastebin.com. The hunter has collected process creation logs, network connections, and script block logging from endpoints. After analyzing the data, the hunter finds several instances of powershell.exe making outbound connections to pastebin.com, but no evidence of file writes or persistence mechanisms. What should the hunter do NEXT in the threat hunting process?
Select an answer first - 32
A threat hunting team must decide between two methodologies for a hunt: (1) analytics-driven hunting using a new user and entity behavior analytics (UEBA) tool, or (2) hypothesis-driven hunting based on a recent industry report about a specific threat group. The team has limited time and must produce actionable findings. Which approach is more likely to yield actionable results quickly?
Select an answer first - 33
A detection engineer is creating a rule to detect credential dumping via LSASS access. The rule must have a low false positive rate because the environment has many legitimate applications that access LSASS. Which approach is most effective?
Select an answer first - 34
A threat hunter is investigating a potential data exfiltration. The hunter has a hypothesis that a specific user account is sending large amounts of data to an external cloud storage service. Which sequence of actions best follows the threat hunting process?
Select an answer first - 35
A security team is deciding between two threat hunting methodologies: IOC-based and analytics-driven. They have a mature SIEM with a large amount of historical data and a threat intelligence platform that provides a steady stream of IOCs. However, they have limited staff and cannot manually review every alert. Which methodology should they choose to maximize detection of unknown threats while managing analyst workload?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.