
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 7Objective 1
Threat Hunting and Detection CTIA Practice Questions (Page 9)
Part of the Threat Hunting and Operational Integration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 41–45
- 41
A threat hunting team has a mature SIEM with a large volume of logs and a dedicated hunting platform. They want to adopt a methodology that is driven by specific hypotheses about attacker behavior, rather than relying on known indicators. Which methodology should they choose?
Select an answer first - 42
Which data source is most likely to provide evidence of lateral movement within a network?
Select an answer first - 43
A company wants to establish a sustainable threat hunting program. They have a small security team that also handles daily alert triage. The management wants to see measurable value from the program within six months. Which approach would BEST help achieve this?
Select an answer first - 44
A detection team has developed a new detection rule and wants to measure its effectiveness before deployment. They have a labeled dataset of 10,000 alerts, of which 500 are true positives. The rule produces 1,200 alerts, of which 400 are true positives. What is the most important metric to evaluate the rule's practical usefulness?
Select an answer first - 45
Which metric is most useful for measuring the effectiveness of a threat hunting program?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.