Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Threat Intelligence Analyst (CTIA)

Domain 1Objective 2

Types of Threat Intelligence (Strategic, Operational, Tactical, Technical) CTIA Practice Questions (Page 2)

Part of the Threat Intelligence Fundamentals domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~4–6 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
6concepts

Questions 6–10

  1. 6application · medium

    A threat intelligence analyst is preparing a report that will be distributed to multiple audiences. The report must include a summary of the threat landscape for executives, a breakdown of recent attack campaigns for security managers, and a list of TTPs for SOC analysts. Which set of intelligence types should the analyst include?

    Select an answer first
  2. 7expert · hard

    A SOC team is overwhelmed by alerts from a recent malware campaign. The team has a list of IOCs from a commercial feed, but many alerts are false positives because the IOCs are too broad. The team lead wants to reduce false positives while still detecting the campaign. The team has access to a detailed analysis of the campaign's TTPs. Which approach is most effective?

    Select an answer first
  3. 8foundation · easy

    Which type of threat intelligence is most likely to be presented to an organization's board of directors?

    Select an answer first
  4. 9foundation · easy

    What does operational threat intelligence primarily focus on?

    Select an answer first
  5. 10expert · hard

    A security engineer is evaluating two threat intelligence feeds. Feed A provides a high volume of IOCs but lacks context about the threat actors or their methods. Feed B provides detailed TTPs and campaign information but includes few IOCs. The engineer needs to improve the SIEM's detection capabilities while also enabling the SOC to understand the threats behind the alerts. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CTIA” is a trademark of its owner, used for identification only.