Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 7Objective 2

Threat Intelligence in SOC Operations, Incident Response, and Risk Management CTIA Practice Questions (Page 11)

Part of the Threat Hunting and Operational Integration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)

55questions here
11free pages
10concepts

Questions 51–55

  1. 51application · medium

    A SOC analyst is triaging a queue of alerts. The threat intelligence feed indicates that a specific malware campaign is currently targeting the organization's sector, and one of the alerts matches an indicator from that campaign. Other alerts are for generic phishing attempts. How should the analyst prioritize the alerts?

    Select an answer first
  2. 52foundation · easy

    Why is collaboration between SOC, IR, and risk management teams important for threat intelligence utilization?

    Select an answer first
  3. 53application · medium

    A SOC is designing a workflow for alert triage. The workflow should automatically enrich alerts with threat intelligence and then route them to the appropriate queue based on severity. Which workflow step is most critical to ensure the enrichment is effective?

    Select an answer first
  4. 54expert · hard

    An organization is in the lessons learned phase of an incident. The IR team found that the threat intelligence feed had indicators for the attacker's infrastructure, but the SOC did not use them because the feed was not integrated into the SIEM. The risk team also wants to update the risk register. What should the organization do to prevent this from recurring?

    Select an answer first
  5. 55expert · hard

    A threat hunting team is planning a proactive hunt. Threat intelligence reports indicate that a specific adversary group has been using living-off-the-land binaries (LOLBins) and PowerShell scripts to evade detection. The team has limited time and must choose a hunting hypothesis. Which hypothesis is most aligned with the intelligence and likely to yield results?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CTIA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.