EC-Council CTIA Module 4.1 Practice Test 003

This practice test covers Module 4 (Data Collection and Processing) Sub-module 1 (Threat Intelligence Data Collection).

These questions are inspired by the EC-Council CTIA exam and are designed to help you test your knowledge of cyber threat intelligence, threats and frameworks, and other related topics. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CTIA exam.

Note: CTIA is a registered trademark of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CTIA practice tests based on specific modules and sub-modules, click that link

EC-Council CTIA Practice Test of the Day 260628
10 questions • Single best answer
Question 1
A collection analyst at an MSSP gathers raw data from open sources, feeds, and internal logs as the first operational step of the lifecycle. They name this activity for a trainee. What is it?
    Question 2
    An analyst gathers intelligence from publicly available sources such as news sites, social media, and public records. They name this discipline. Which collection source is it?
      Question 3
      An analyst obtains intelligence through interactions with people, such as informants and trusted industry contacts. They classify this source. Which collection discipline is it?
        Question 4
        An analyst collects data about a target without directly touching its systems, leaving no detectable footprint. They name this approach. Which collection method is it?
          Question 5
          An analyst directly probes a target's infrastructure, scanning and interacting with its services to gather data. They classify this approach. Which collection method does it describe?
            Question 6
            An analyst pulls indicators from the organization's own SIEM, firewall logs, and incident records. They categorize where these came from. Which source type are they?
              Question 7
              An analyst receives indicator data in a consistent, machine-readable format like STIX with clearly defined fields. They classify this data. Which type is it?
                Question 8
                An analyst must extract indicators from free-form blog posts and PDF reports that follow no consistent format. They classify this data. Which type is it?
                  Question 9
                  An analyst derives intelligence from intercepted communications and electronic signals. They name this discipline. Which collection source is it?
                    Question 10
                    An analyst stresses that without first gathering relevant raw data, later analysis has nothing to work with. A peer asks what this phase delivers. What does collection primarily provide?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top