
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 7Objective 2
Threat Intelligence in SOC Operations, Incident Response, and Risk Management CTIA Practice Questions (Page 1)
Part of the Threat Hunting and Operational Integration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 1–5
- 1
During a major incident, the SOC identifies a new malware variant and creates indicators of compromise (IOCs). The IR team is containing the incident, and the risk team needs to assess the potential business impact. How should the teams coordinate to ensure effective response and risk management?
Select an answer first - 2
A SOC analyst is triaging alerts during a shift. The threat intelligence feed has just been updated with a new indicator for an active ransomware campaign. One alert matches this new indicator, while other alerts are for low-severity policy violations. What should the analyst do first?
Select an answer first - 3
A SOC team wants to design a workflow that uses threat intelligence to improve alert triage. The goal is to reduce the time analysts spend on false positives while ensuring that high-priority alerts are escalated. Which workflow design best achieves this?
Select an answer first - 4
Which step in an intelligence-driven SOC workflow would most likely involve updating threat intelligence based on findings from an investigation?
Select an answer first - 5
Which practice best supports coordination between SOC, IR, and risk teams regarding threat intelligence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.