
EC-CouncilCertified Threat Intelligence Analyst (CTIA)
Domain 3Objective 1
Threat Intelligence Program Requirements and Planning CTIA Practice Questions (Page 1)
Part of the Requirements, Planning and Direction domain, which makes up ~14% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–11 in this domain), expect 4–6 from this objective — we provide 68 practice questions to prepare you well beyond it. (estimate)
68questions here
14free pages
16concepts
Questions 1–5
- 1
A threat intelligence team produces a detailed analysis of a new phishing campaign targeting the organization's employees. The analysis includes technical indicators, campaign tactics, and recommended mitigations. Which dissemination approach is most appropriate?
Select an answer first - 2
A threat intelligence analyst discovers a vulnerability in a third-party product used by the organization. The analyst wants to share this information with a national CERT. The organization's legal team is concerned about potential liability and data privacy regulations. What should the analyst do?
Select an answer first - 3
A global manufacturing company is establishing a threat intelligence program. The company has a high risk of intellectual property theft from state-sponsored actors, a moderate risk of ransomware attacks, and a low risk of hacktivist activity. The program has limited resources and must prioritize its intelligence requirements. The board has requested strategic intelligence on long-term threats to the company's competitive advantage, while the SOC needs tactical indicators for immediate defense. Which prioritization approach best balances these competing needs?
Select an answer first - 4
A financial services company is drafting the charter for its threat intelligence program. The program will collect data from external sources, including dark web forums, and will share intelligence with industry partners. The legal department is concerned about regulatory compliance and liability. The CISO wants the program to be agile and responsive to emerging threats. Which charter provision is most critical to include?
Select an answer first - 5
A threat intelligence team has identified a critical vulnerability in a widely used software product that affects the organization. The team needs to communicate this to various stakeholders, including the executive team, the IT operations team, and the legal department. The vulnerability is not yet publicly disclosed, and there is a risk of exploitation. What is the most appropriate communication approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.