
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 5Objective 2
Threat Intelligence Evaluation and Runbook Creation CTIA Practice Questions (Page 2)
Part of the Data Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
6concepts
Questions 6–10
- 6
An analyst is developing a runbook for handling a data breach involving stolen credentials. The runbook must define triggers, steps, roles, and decision points. Which element is a trigger for initiating the runbook?
Select an answer first - 7
Which component is typically included in the structure of a threat intelligence runbook?
Select an answer first - 8
What is the first step in developing a threat intelligence runbook?
Select an answer first - 9
A SOC manager is reviewing the runbook for a ransomware incident. The runbook is comprehensive, but it is 15 pages long and includes detailed steps for every possible scenario. The SOC team has complained that it is too complex and difficult to follow during a high-pressure incident. What is the most appropriate action for the manager to take?
Select an answer first - 10
A multinational organization is evaluating two threat intelligence sources: a commercial feed that provides real-time IOCs with high confidence scores, and an open-source feed that provides contextual reports but with a 24-hour delay. The organization's SOC has a limited budget and must decide which source to integrate. The SOC's primary concern is reducing false positives in their SIEM. Which approach best balances the trade-offs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.