
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 5Objective 2
Threat Intelligence Evaluation and Runbook Creation CTIA Practice Questions (Page 6)
Part of the Data Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
6concepts
Questions 26–30
- 26
What is the main benefit of integrating threat intelligence runbooks into security operations workflows?
Select an answer first - 27
What is the primary purpose of scoring and prioritizing threat intelligence?
Select an answer first - 28
A security operations center (SOC) is creating a runbook for handling a suspected malware infection on a user's workstation. What is the primary purpose of this runbook?
Select an answer first - 29
A SOC is developing a runbook for a new type of attack that exploits a vulnerability in a legacy system. The runbook must be integrated into the existing incident response workflow. The team has limited resources and must decide whether to create a new runbook or modify an existing one. Which approach is most effective?
Select an answer first - 30
A threat intelligence analyst is developing a runbook for a new type of ransomware that encrypts files and demands payment. The runbook must guide the incident response team through containment and eradication. Which step should be included as a decision point in the runbook?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.