EC-Council CTIA Module 6.1 Practice Test 002

This practice test covers Module 6 (Intelligence Reporting and Dissemination) Sub-module 1 (Threat Intelligence Reports).

These questions are inspired by the EC-Council CTIA exam and are designed to help you test your knowledge of cyber threat intelligence, threats and frameworks, and other related topics. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CTIA exam.

Note: CTIA is a registered trademark of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CTIA practice tests based on specific modules and sub-modules, click that link

EC-Council CTIA Module 6.1 Practice Test 002
10 questions • Single best answer
Question 1
A threat intelligence lead at a national energy provider briefs the board each quarter. The board wants long-term adversary trends and geopolitical risk rather than technical indicators. Which report type best fits this audience?
    Question 2
    An analyst at an MSSP drafts a threat report, but clients say it does not help them respond. A reviewer notes it states findings without telling readers what to do. What element should be added?
      Question 3
      A SOC team supporting a retail chain requests intelligence on specific malware hashes and malicious domains for immediate blocking. They need short-lived, machine-readable data. Which intelligence report type serves this need?
        Question 4
        A CTI team standardizes its output and wants a platform to author, template, and format finished intelligence products consistently. They evaluate options focused on document creation rather than data collection. Which tool category fits?
          Question 5
          After finishing a report, an analyst must deliver it to stakeholders with different needs and clearance levels. The team debates how to package and route the finished product. Which lifecycle phase does this represent?
            Question 6
            A government CERT produces intelligence describing an adversary's upcoming campaign, intended targets, and likely timing. Decision-makers use it to anticipate threats over the coming weeks. Which intelligence type is this?
              Question 7
              An intelligence report is sent to senior leaders who lack time for deep technical detail. They request a concise, high-level overview placed at the top of every report. Which component meets this?
                Question 8
                A threat analyst must convey uncertainty about attribution without overstating it. A senior reviewer recommends calibrated wording that signals degrees of certainty. What reporting practice does this reflect?
                  Question 9
                  A new analyst submits a 'report' that is simply an exported list of IP addresses from a feed. The lead explains this is unprocessed data, not a finished intelligence product. What is missing that defines intelligence?
                    Question 10
                    A CTI program shares technical indicators with partners and needs a structured, machine-readable format for the report content. They want partner tools to ingest it automatically. Which standard supports this?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top