
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 4Objective 1
Threat Intelligence Data Collection CTIA Practice Questions (Page 14)
Part of the Data Collection and Processing domain, which makes up ~29% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 8–12 from this objective — we provide 175 practice questions to prepare you well beyond it. (estimate)
175questions here
35free pages
62concepts
Questions 66–70
- 66
An analyst wants to automate the collection of open-source intelligence (OSINT) about a specific threat actor. The analyst needs to gather data from social media, forums, and public repositories. Which tool would be most suitable?
Select an answer first - 67
A financial institution is developing a threat intelligence data collection plan. The organization's key intelligence requirements (KIRs) focus on identifying phishing campaigns targeting customers and understanding the tactics used by a specific threat actor group. The analyst must decide which data sources to prioritize. Which combination of sources best aligns with the KIRs?
Select an answer first - 68
After a significant security incident, a threat intelligence analyst is tasked with reviewing the incident response (IR) report to extract lessons and indicators for future collection. The analyst wants to improve the organization's data collection processes based on the findings. Which action would be most effective?
Select an answer first - 69
An organization suspects an insider threat is exfiltrating sensitive data. The security team needs to collect internal data to investigate. Which internal sources should be prioritized to identify unauthorized access and data exfiltration?
Select an answer first - 70
A security operations center (SOC) is investigating a potential insider threat. The analyst has access to authentication logs, endpoint detection and response (EDR) data, and employee access records. The goal is to identify any unauthorized access or data exfiltration by an employee. Which data source combination would provide the most comprehensive evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.