EC-Council CTIA Module 2.2 Practice Test 003

This practice test covers Module 2 (Introduction to Threat Intelligence) Sub-module 2 (Advanced Persistent Threats).

These questions are inspired by the EC-Council CTIA exam and are designed to help you test your knowledge of cyber threat intelligence, threats and frameworks, and other related topics. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CTIA exam.

Note: CTIA is a registered trademark of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CTIA practice tests based on specific modules and sub-modules, click that link

EC-Council CTIA Practice Test of the Day 260626
10 questions • Single best answer
Question 1
A CTI program manager at a government agency studies an adversary that gained covert access, moved laterally, and exfiltrated data slowly over many months. The group is well-resourced and highly targeted. Which class of attack is this?
    Question 2
    Analysts note an intruder avoided noisy actions, used legitimate credentials, and stayed hidden for a long dwell time. This behavior defines a hallmark of sophisticated campaigns. Which characteristic is described?
      Question 3
      An analyst maps an APT campaign to its lifecycle. The earliest activity involved researching employees and harvesting credentials to gain a foothold. Which phase does this represent?
        Question 4
        After gaining a foothold, the adversary moved from host to host, escalating privileges to reach valuable servers. The goal was expanding internal access. Which APT lifecycle phase is this?
          Question 5
          A defense firm's leadership asks who typically runs these prolonged, well-funded operations against strategic targets. The analyst explains the usual sponsors. Which group most commonly conducts such campaigns?
            Question 6
            During an APT investigation, analysts find malware beaconing to external infrastructure to receive instructions and updates. This channel sustains attacker control. Which lifecycle element is this?
              Question 7
              An analyst contrasts APTs with commodity attacks. Unlike smash-and-grab crime, this actor prioritized sustained covert collection of sensitive information. What primarily motivates such an actor?
                Question 8
                Investigators measure how long the adversary remained undetected inside the network before discovery. This metric is central to evaluating campaign impact. What is this duration called?
                  Question 9
                  In the final stages, the adversary compressed and encrypted stolen files, then transferred them out through an allowed protocol to avoid suspicion. Which APT lifecycle phase is occurring?
                    Question 10
                    A SOC must classify an incident. The activity is targeted, persistent, multi-stage, and human-operated rather than automated and widespread. How should it be categorized?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top