Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 4Objective 1

Threat Intelligence Data Collection CTIA Practice Questions (Page 28)

Part of the Data Collection and Processing domain, which makes up ~29% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 8–12 from this objective — we provide 175 practice questions to prepare you well beyond it. (estimate)

175questions here
35free pages
62concepts

Questions 136–140

  1. 136foundation · easy

    During a threat intelligence investigation, an analyst needs to review records of successful and failed login attempts, including timestamps and source IP addresses. Which type of log is the primary source for this data?

    Select an answer first
  2. 137expert · hard

    A threat intelligence team in the energy sector is tasked with collecting intelligence on supply chain risks from third-party vendors. The team has limited resources and must decide between two approaches: (1) subscribing to a general-purpose threat intelligence feed that includes supply chain indicators, or (2) joining an energy-sector information sharing and analysis center (ISAC) that provides vendor-specific threat reports. The team's primary requirement is to identify vulnerabilities in vendors that could impact operational technology (OT) systems. Which approach is more appropriate?

    Select an answer first
  3. 138expert · hard

    A security team wants to collect data on attacker behavior and tactics targeting their network. They are considering deploying a honeypot. Which consideration is most critical for the success of the honeypot?

    Select an answer first
  4. 139foundation · easy

    What type of threat-related information is commonly found on online forums?

    Select an answer first
  5. 140foundation · easy

    During the data collection phase, a threat intelligence analyst needs to gather indicators from public websites, including malicious URLs, IP addresses, and file hashes. Which type of data source is most directly associated with this activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.