EC-Council CTIA Module 1.2 Practice Test 003

This practice test covers Module 1 (Introduction to Threat Intelligence) Sub-module 2 (Cyber Threat Intelligence Concepts).

These questions are inspired by the EC-Council CTIA exam and are designed to help you test your knowledge of cyber threat intelligence, threats and frameworks, and other related topics. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CTIA exam.

Note: CTIA is a registered trademark of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CTIA practice tests based on specific modules and sub-modules, click that link

EC-Council CTIA Practice Test of the Day 260625
10 questions • Single best answer
Question 1
A SOC analyst at a healthcare network receives daily feeds of malicious IPs and file hashes. Her team lead stresses that these raw artifacts only become useful once processed and given meaning. Which best describes that refined output?
    Question 2
    A threat intelligence lead prepares a quarterly briefing for the board on geopolitical risks and long-term adversary trends. The material deliberately avoids technical indicators and emphasizes business impact. Which type of intelligence is being delivered?
      Question 3
      A threat hunter on an MSSP team analyzes adversary TTPs to improve detection rules and security controls. The output directly guides defenders in their day-to-day configuration work. Which intelligence type does this represent?
        Question 4
        An incident response team requests details on an imminent campaign targeting their sector, including likely timing and attacker infrastructure. The aim is to anticipate one specific upcoming attack. Which intelligence category fits this need?
          Question 5
          An analyst at a financial services firm ingests specific malicious hashes, IPs, and domains into detection tools. These short-lived artifacts feed automated blocking with little human review. Which intelligence type describes this feed?
            Question 6
            A risk manager contrasts the organization's legacy security posture with its new CTI program. She observes that the older approach mostly reacted only after incidents had already occurred. What key advantage does threat intelligence add?
              Question 7
              A new hire asks what a cyber threat intelligence analyst primarily does beyond gathering feeds. The mentor describes interpreting adversary behavior and producing actionable findings for stakeholders. Which task best reflects this role?
                Question 8
                A CTI team transforms collected and processed data into finished products that inform decisions. A stakeholder asks what this overall creation process is properly called. Which term applies?
                  Question 9
                  An intelligence team maps each product to its primary audience. They need to identify who consumes high-level reports on long-term risk and major investment decisions. Which audience is the main consumer?
                    Question 10
                    A cloud security engineer collects large volumes of unprocessed logs, IPs, and alerts from sensors. A colleague clarifies that without interpretation these remain merely inputs. What are these unrefined inputs called?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top