
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 4Objective 1
Threat Intelligence Data Collection CTIA Practice Questions (Page 4)
Part of the Data Collection and Processing domain, which makes up ~29% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 8–12 from this objective — we provide 175 practice questions to prepare you well beyond it. (estimate)
175questions here
35free pages
62concepts
Questions 16–20
- 16
What is the main advantage of dynamic malware analysis over static analysis?
Select an answer first - 17
Why are legal and regulatory sources important for threat intelligence collection?
Select an answer first - 18
A threat intelligence analyst is reviewing network device logs to identify indicators of compromise. Which log source provides the most direct evidence of a successful or attempted exploit against a specific host?
Select an answer first - 19
A security team is analyzing a targeted phishing campaign against their organization. The team has access to email gateway logs, a sandbox for analyzing attachments, and threat intelligence feeds. The team's goal is to collect indicators of compromise (IOCs) and understand the social engineering tactics used. Which approach would yield the most comprehensive intelligence?
Select an answer first - 20
In the context of threat intelligence data collection, what is the primary purpose of continuous monitoring?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.