EC-Council CTIA Module 5.7 Practice Test 002

This practice test covers Module 5 (Data Analysis) Sub-module 7 (Create Runbooks and Knowledge Base).

These questions are inspired by the EC-Council CTIA exam and are designed to help you test your knowledge of cyber threat intelligence, threats and frameworks, and other related topics. Some questions require multiple correct answers.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the skills and knowledge tested in the CTIA exam.

Note: CTIA is a registered trademark of EC-Council. This content is not affiliated with or endorsed by EC-Council.

To choose CTIA practice tests based on specific modules and sub-modules, click that link

EC-Council CTIA Module 5.7 Practice Test 002
10 questions • Single best answer
Question 1
A threat hunting team at an MSSP wants documented, repeatable steps so any analyst can respond uniformly to a recurring malware alert. They need a standardized operational procedure rather than ad-hoc actions. What artifact best meets this need?
    Question 2
    An analyst at a cloud service provider is building a centralized repository storing past incidents, adversary TTPs, and prior analytical findings. New team members will reference it to learn institutional history. What is this repository called?
      Question 3
      A new CTI lead asks how a runbook differs from the team's knowledge base. One captures procedural response steps; the other preserves analytical context for later lookup. Which option describes the knowledge base?
        Question 4
        An incident response team repeatedly handles credential-phishing alerts inconsistently across shifts. Leadership wants a documented procedure ensuring every analyst follows identical containment and eradication steps. Which solution addresses this?
          Question 5
          A SOC integrates its runbooks with a SOAR platform so common procedures execute without manual analyst input. The goal is faster, consistent handling of routine alerts. What does this primarily achieve?
            Question 6
            A growing CTI team loses institutional knowledge whenever senior analysts leave. A manager wants a maintained repository capturing lessons learned and historical adversary activity for future reference. What should the team establish?
              Question 7
              During a procedure review, an analyst notes one response guide references outdated containment tools no longer in use. The team must keep these operational guides accurate over time. What practice does this highlight?
                Question 8
                A financial-sector CTI team documents a step-by-step workflow for triaging suspicious IoC matches, including decision points and escalation paths. They want analysts to follow it during alerts. What type of artifact are they producing?
                  Question 9
                  An analyst wants to quickly look up how a previously observed APT group operated during an earlier intrusion. The information was archived after that case closed. Which resource should she consult?
                    Question 10
                    A CTI manager argues that runbooks and a knowledge base serve complementary roles in analysis operations. One drives consistent action; the other preserves organizational memory. Which best summarizes the knowledge base's primary value?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top