EC-Council CTIA Module 2.3 Practice Test 003

This practice test covers Module 2 (Introduction to Threat Intelligence) Sub-module 3 (Cyber Kill Chain).

These questions are inspired by the EC-Council CTIA exam and are designed to help you test your knowledge of cyber threat intelligence, threats and frameworks, and other related topics. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CTIA exam.

Note: CTIA is a registered trademark of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CTIA practice tests based on specific modules and sub-modules, click that link

EC-Council CTIA Practice Test of the Day 260626
10 questions • Single best answer
Question 1
A threat hunter at a cloud services provider maps an intrusion to a seven-stage Lockheed Martin model describing attacker progression. The earliest stage involves gathering information about the target. Which model is being applied?
    Question 2
    An analyst reviews early attacker activity: scanning the perimeter, harvesting emails, and profiling employees on social media. No payload has been delivered yet. Which kill chain stage is this?
      Question 3
      After researching the target, the adversary pairs a remote-access trojan with a malicious document to create a deliverable payload. No contact with the victim has happened. Which stage is occurring?
        Question 4
        An analyst sees the attacker transmit a malicious attachment to victims through a phishing email. The payload has not yet executed. Which kill chain stage does this represent?
          Question 5
          Logs show the malicious code triggered a software flaw the moment a user opened the file, running attacker code on the host. Which kill chain stage is this?
            Question 6
            After code execution, the malware writes itself to disk and creates a registry run key so it survives reboots. This establishes a persistent foothold. Which stage is this?
              Question 7
              The implant beacons to an external server, opening a channel for the operator to send remote commands. Which kill chain stage does this match?
                Question 8
                In the final stage, the adversary collects and exfiltrates sensitive data, achieving the campaign's goal. Which kill chain stage is this?
                  Question 9
                  A SOC lead explains why the team maps attacks to the model: disrupting any single stage can break the entire sequence. What is the primary defensive benefit of this approach?
                    Question 10
                    An analyst wants a linear, stage-based model originally from Lockheed Martin rather than a detailed matrix of granular techniques. Which framework should be chosen?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top