Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 5Objective 2

Threat Intelligence Evaluation and Runbook Creation CTIA Practice Questions (Page 7)

Part of the Data Analysis domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
6concepts

Questions 31–35

  1. 31application · medium

    A security analyst is evaluating two threat intelligence feeds for a financial institution. Feed A provides detailed indicators of compromise (IOCs) with a 24-hour delay, sourced from a well-known vendor with a strong track record. Feed B provides real-time IOCs from an anonymous researcher's blog, which has been accurate in the past but occasionally publishes unverified data. The institution needs to block an active phishing campaign targeting its customers. Which feed should the analyst prioritize, and why?

    Select an answer first
  2. 32foundation · easy

    Which factor is most important when prioritizing threat intelligence for immediate action?

    Select an answer first
  3. 33application · medium

    A threat intelligence analyst is evaluating a new commercial threat intelligence feed. The vendor claims a high confidence score for its indicators. What is the most important factor for the analyst to verify about this confidence score?

    Select an answer first
  4. 34application · medium

    A security operations center (SOC) is creating a runbook for responding to a phishing campaign that uses a specific malware dropper. The runbook should standardize the response actions. Which element is most essential to include in the runbook?

    Select an answer first
  5. 35application · medium

    A company is developing a runbook for a new type of attack that involves the abuse of a legitimate remote access tool. The runbook must include steps for the SOC, the incident response team, and the system administrators. What is the most important element to define in the runbook to ensure a coordinated response?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.