Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 5Objective 2

Threat Intelligence Evaluation and Runbook Creation CTIA Practice Questions (Page 1)

Part of the Data Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
6concepts

Questions 1–5

  1. 1application · medium

    An analyst finds a new malware sample and extracts a domain name that it communicates with. The domain was registered three days ago. To validate this as a malicious domain, what is the most important additional piece of evidence to gather?

    Select an answer first
  2. 2expert · hard

    A threat intelligence analyst is scoring a new indicator: a command-and-control (C2) domain. The domain is highly relevant to the organization's industry and has a high confidence score from a reputable source. However, the domain is not currently active and has not been seen in the organization's network. How should the analyst score this indicator?

    Select an answer first
  3. 3expert · medium

    An analyst is validating a report that a specific file hash is associated with a new trojan. The report comes from a single commercial source. The analyst has access to a sandbox that can execute the file, but the file is not yet available. The analyst also has access to a threat intelligence platform that aggregates multiple sources. Which action is most appropriate to validate the report?

    Select an answer first
  4. 4application · medium

    A security team has implemented a runbook for incident response. To ensure the runbook is effectively integrated into the SOC's workflow, which action should be taken?

    Select an answer first
  5. 5application · medium

    A SOC receives a high-priority alert from its SIEM about a potential data exfiltration. The alert is based on a new detection rule. The on-call analyst is unsure if the rule has been tested. What should the analyst do first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.