EC-Council CTIA Module 1.1 Practice Test 003

This practice test covers Module 1 (Introduction to Threat Intelligence) Sub-module 1 (Intelligence).

These questions are inspired by the EC-Council CTIA exam and are designed to help you test your knowledge of cyber threat intelligence, threats and frameworks, and other related topics. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CTIA exam.

Note: CTIA is a registered trademark of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CTIA practice tests based on specific modules and sub-modules, click that link

EC-Council CTIA Practice Test of the Day 260625
10 questions • Single best answer
Question 1
A newly hired analyst at a critical infrastructure operator reviews raw logs, then contextualized findings, and finally an evaluated, decision-ready product. They want the correct term for this refined output that guides leadership choices. Which best describes it?
    Question 2
    A SOC team at a retail chain collects thousands of unprocessed log entries and IP addresses. A manager asks what to call these isolated, unanalyzed facts before any context is applied. Which term applies?
      Question 3
      A vendor sells a feed of millions of malicious IPs and hashes with no context or analysis attached. A CTI lead at a bank explains this offering is not the same as true intelligence. What does the feed actually represent?
        Question 4
        An instructor asks a class to name the four standard categories used to organize threat intelligence outputs by audience and detail level. A student lists them aloud. Which set is correct?
          Question 5
          A CTI team prepares a high-level report on geopolitical risks and long-term adversary trends for the board of directors. The content avoids technical detail and supports executive decisions. Which type of intelligence is this?
            Question 6
            An analyst documents adversary tools, techniques, and procedures so SOC defenders can tune detections. The output is consumed mainly by security operations staff for everyday defense. Which intelligence type does this describe?
              Question 7
              A CTI team studies the intent, timing, and likely targets of a specific upcoming adversary campaign against a healthcare network. The findings help anticipate one particular attack. Which intelligence type best fits?
                Question 8
                An analyst feeds malicious hashes, IP addresses, and domains directly into security controls for automated blocking. These atomic indicators are often short-lived. Which intelligence type does this represent?
                  Question 9
                  A risk manager contrasts traditional, reactive security controls with a CTI-driven approach. She notes the main advantage of intelligence is acting before an attack rather than after one occurs. What does this advantage best illustrate?
                    Question 10
                    A manager defines the core duties of a cyber threat analyst who collects, processes, and analyzes adversary data to produce actionable outputs for stakeholders. Which best summarizes this primary responsibility?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top