EC-Council CTIA Module 3.1 Practice Test 003

This practice test covers Module 3 (Planning, Direction, and Review) Sub-module 1 (Organization’s Current Threat Landscape).

These questions are inspired by the EC-Council CTIA exam and are designed to help you test your knowledge of cyber threat intelligence, threats and frameworks, and other related topics. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CTIA exam.

Note: CTIA is a registered trademark of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CTIA practice tests based on specific modules and sub-modules, click that link

EC-Council CTIA Practice Test of the Day 260628
10 questions • Single best answer
Question 1
A CTI program manager at a manufacturing firm begins by cataloging the organization's most valuable systems and the adversaries targeting them. This baseline guides where defenses should focus. What is this foundational activity called?
    Question 2
    An analyst identifies the systems whose compromise would cause the greatest business damage, such as the patient database and payment platform. These get top protection priority. What are these high-value systems commonly called?
      Question 3
      An analyst enumerates every internet-facing service, exposed API, and remote access point an adversary could target. They need a term for this total set of exposure points. Which concept describes it?
        Question 4
        An analyst at a bank lists ransomware crews and fraud-focused groups known to target financial services. They match each to the firm's exposure. What does this analysis help the program do?
          Question 5
          Leadership asks why one threat ranks above others on the program's list. The analyst explains it could most severely disrupt the revenue-generating platform. Which factor is driving this prioritization?
            Question 6
            A CTI lead maps the organization's threat picture before designing the intelligence program. A colleague questions why this comes first. What is the main reason for establishing this baseline?
              Question 7
              An executive requests the overall picture of adversaries, vulnerabilities, and attack trends currently relevant to the organization. The analyst names this complete view. Which term captures it?
                Question 8
                An analyst filters a global threat report to keep only adversaries plausibly targeting their cloud-hosted SaaS product. Irrelevant entries are discarded. What is the value of this filtering step?
                  Question 9
                  A team reviews unpatched systems and misconfigurations that adversaries could exploit against critical assets. They need a precise label for these weaknesses. What are they called?
                    Question 10
                    After mapping critical assets and likely adversaries, a team uses the findings to define what intelligence the program must produce. Which subsequent phase does this assessment directly feed?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top