EC-Council CTIA Module 1.3 Practice Test 003

This practice test covers Module 1 (Introduction to Threat Intelligence) Sub-module 3 (Intelligence Lifecycle and Frameworks).

These questions are inspired by the EC-Council CTIA exam and are designed to help you test your knowledge of cyber threat intelligence, threats and frameworks, and other related topics. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CTIA exam.

Note: CTIA is a registered trademark of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CTIA practice tests based on specific modules and sub-modules, click that link

EC-Council CTIA Practice Test of the Day 260625
10 questions • Single best answer
Question 1
A CTI program manager at a federal agency is launching a new intelligence effort. Before any data is gathered, she works with stakeholders to define objectives and the questions intelligence must answer. Which lifecycle phase is she performing?
    Question 2
    An analyst at an MSSP is documenting the intelligence lifecycle for a training guide. He needs to identify the stage that immediately follows the gathering of raw data. Which stage comes next in the sequence?
      Question 3
      A threat intelligence team has finished examining a campaign and produced a finished report for executives. The lead now focuses on delivering the product to the right consumers in a usable format. Which lifecycle phase does this represent?
        Question 4
        After distributing a strategic report, a CTI lead at a bank surveys consumers to learn whether the intelligence met their needs. The responses will shape future requirements and collection priorities. Which lifecycle phase captures this activity?
          Question 5
          A junior analyst converts collected logs into a normalized, structured format and removes duplicates before interpretation begins. He confuses this step with the stage where meaning and context are derived. Which phase is he actually performing?
            Question 6
            A CISO wants to benchmark how advanced her organization's intelligence capability is, from ad-hoc efforts to fully integrated, automated programs. She seeks a model that defines progressive capability levels. Which model best fits this need?
              Question 7
              A new threat intelligence director defines long-term goals, scope, and how intelligence supports business objectives across the enterprise. This high-level plan guides program priorities and resource allocation. What is this best called?
                Question 8
                A CTI team wants a standardized structure to guide consistent collection, analysis, and adversary modeling across analysts. They evaluate established structures rather than building ad-hoc methods. What do these structures collectively represent?
                  Question 9
                  During the lifecycle, an analyst correlates processed data, applies techniques like ACH, and produces assessments about adversary intent. He then prepares findings for the report. Which phase produces these assessments?
                    Question 10
                    Following defined requirements, a team gathers data from OSINT, commercial feeds, and internal logs. This activity supplies raw inputs into the next stage of the cycle. Which phase is being executed?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top