
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 4Objective 1
Threat Intelligence Data Collection CTIA Practice Questions (Page 27)
Part of the Data Collection and Processing domain, which makes up ~29% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 8–12 from this objective — we provide 175 practice questions to prepare you well beyond it. (estimate)
175questions here
35free pages
62concepts
Questions 131–135
- 131
A threat intelligence analyst is building a collection plan for a financial services firm. The firm's priority intelligence requirement is to identify phishing domains targeting its customers. The analyst has identified three potential sources: a commercial threat feed that has historically provided high-fidelity indicators but with a 48-hour delay, a public paste site where new phishing URLs often appear within minutes but with many false positives, and an internal email gateway log that captures actual phishing attempts against the firm. The analyst needs to balance timeliness, accuracy, and relevance. Which approach best aligns with the intelligence requirement?
Select an answer first - 132
Why is it important for a data collection plan to align with organizational objectives?
Select an answer first - 133
An organization's threat intelligence team is about to dispose of a set of hard drives that previously stored sensitive threat intelligence reports. Which of the following methods is the MOST appropriate to ensure the data cannot be recovered?
Select an answer first - 134
What is the primary output of static malware analysis?
Select an answer first - 135
Which of the following best describes the primary purpose of threat intelligence sharing platforms (TISPs) such as MISP, ThreatConnect, or Anomali?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.