
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 7Objective 1
Threat Hunting and Detection CTIA Practice Questions (Page 8)
Part of the Threat Hunting and Operational Integration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 36–40
- 36
A security analyst at a mid-sized company notices an unusual pattern: several workstations are making DNS queries to a rarely-used domain at 3:00 AM, but no alerts have fired. The analyst wants to determine whether this is malicious activity. Which approach best aligns with a hypothesis-driven threat hunting process?
Select an answer first - 37
Which statement best describes the role of threat hunting in a defense-in-depth strategy?
Select an answer first - 38
What is the main goal of testing detection rules before deployment?
Select an answer first - 39
What is the first step in a systematic threat hunting process?
Select an answer first - 40
A detection team has created a new detection rule for a known adversary technique. Before deploying it to production, they want to ensure it works and does not generate excessive false positives. What is the best validation approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.