Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 7Objective 2

Threat Intelligence in SOC Operations, Incident Response, and Risk Management CTIA Practice Questions (Page 9)

Part of the Threat Hunting and Operational Integration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 4–5 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)

55questions here
11free pages
10concepts

Questions 41–45

  1. 41foundation · easy

    In an intelligence-driven SOC workflow, what is the primary role of threat intelligence during alert triage?

    Select an answer first
  2. 42expert · hard

    A risk manager is prioritizing mitigation efforts for a set of identified risks. The threat intelligence indicates that a specific vulnerability is being actively exploited in the wild, but the organization has compensating controls that reduce the likelihood of exploitation. Another vulnerability has a higher CVSS score but is not currently being exploited. How should the risk manager prioritize?

    Select an answer first
  3. 43expert · hard

    A risk analyst is enhancing the organization's risk scoring model. The model currently uses asset value, vulnerability severity, and control effectiveness. The analyst wants to incorporate threat intelligence to better reflect the current threat landscape. The organization has a limited budget and cannot implement a full TIP. What is the most effective approach?

    Select an answer first
  4. 44expert · hard

    A SOC is integrating a new threat intelligence feed into its SIEM. The feed contains a high volume of indicators, but many are outdated or have low confidence. The SOC wants to avoid overwhelming analysts with false positives while still detecting genuine threats. Which integration strategy is most effective?

    Select an answer first
  5. 45expert · hard

    A risk manager is updating the organization's risk register. Threat intelligence indicates that a specific adversary group is actively targeting the organization's industry and has recently exploited a vulnerability in a legacy application that the organization still uses. The application is scheduled for decommissioning in six months. The risk manager must decide how to treat this risk. Which decision best balances risk reduction and business constraints?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.