10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
These 10 free CCTA questions are organized by exam domain, so you can see how each part of the Board Certification in Civil Trial Law blueprint is tested. Reveal the answer and explanation under each question.
Domain 2: Evaluation, Remedies and Defenses
Question 1
A team has preserved 60 public voice messages relevant to today's facility-threat briefing. The messages are in two languages the analysts do not understand. No checked transcripts or translations exist, so the team cannot tell whether speakers are making plans or quoting news. Funding is available for one additional task before the briefing. Where would it remove the immediate bottleneck?
Show answer & explanation
Correct answer: C - Produce checked transcripts and translations of the collected messages.
Domain 3: Jurisdiction, Venue and Joinder
Question 2
During a voluntary interview, a former employee describes a private conversation they personally heard. The investigator makes a digital recording. Separately, an analyst reviews the employee's old public blog posts. For collection tagging, the interview and the blog review are, respectively:
Show answer & explanation
Correct answer: D - HUMINT and OSINT: direct human reporting, followed by review of public source material.
Domain 4: Practice and Procedures
Question 3
A source marks a technical advisory TLP:GREEN and defines its community as the member organizations of a regional incident-response consortium. A response lead at another member organization needs the advisory. No additional restrictions apply. Which instruction correctly applies the TLP 2.0 sharing boundary?
Show answer & explanation
Correct answer: A - Share it with the other member through the consortium's restricted portal, retaining the TLP:GREEN label.
Domain 5: Evidence
Question 4
An analyst examines an untrusted document in a VirtualBox 7.1 VM with its network adapter disconnected. A writable host shared folder holds working evidence. The document's process overwrites a file in that folder. Restoring a VM snapshot repairs the guest disk but leaves the host file altered. Which preventive change addresses the demonstrated path?
Show answer & explanation
Correct answer: A - Make the host evidence share read-only, using disposable guest copies for work that requires writing.
An enrichment feed merges two profiles because both carry account ID 7319. One profile is on a professional network; the other is on a discussion forum. Each service assigns IDs only within its own platform. The profiles use the same stock photograph but different handles. During entity-resolution review, how should these records be represented?
Show answer & explanation
Correct answer: B - Separate platform accounts; the evidence does not establish a common operator.
More CCTA practice questions
Question 6
An online seller advertises "newly stolen engineering drawings." Analysts are comparing two explanations: possession of recent nonpublic material, or repackaging of a leak from two years ago. The publicly posted sample contains genuine company drawings. The team may compare that sample with the company's authorized design repository. Which finding would most strongly distinguish the two explanations?
Show answer & explanation
Correct answer: C - A sample page contains a nonpublic design change first created after the older leak.
Question 7
A suspicious email contains these abridged Received fields, listed from top to bottom:
1. from edge.example.org [192.0.2.10] by inbox.example.org [192.0.2.105]
2. from relay.example.net [198.51.100.8] by edge.example.org
3. from finance-pc [203.0.113.240] by relay.example.net
The first two fields were added by the organization's trusted mail servers. Which IP identifies the external host that handed the message to that trusted infrastructure?
Show answer & explanation
Correct answer: A - 198.51.100.8
Question 8
An impersonation-detection model is tested on independently reviewed accounts representative of its intended workload. Of 100 impersonation accounts, it flags 80. Of 9,900 genuine accounts, it flags 198. A manager says the 80% detection rate means four of every five flagged accounts are impersonators. Which interpretation should replace that claim?
Show answer & explanation
Correct answer: D - About 29% of flagged accounts are impersonators; flags can prioritize corroboration rather than establish identity.
Question 9
An authorized, internally consistent phone acquisition includes chat.db, chat.db-wal, and chat.db-shm. The messaging app used SQLite write-ahead logging. An examiner copies only chat.db into a separate work folder, queries it, finds no messages from the final hour, and concludes that a screenshot from that hour was fabricated. Before accepting that conclusion, what examination is most probative?
Show answer & explanation
Correct answer: B - Examine matching chat.db and chat.db-wal working copies for committed messages not yet checkpointed into the main database.
Question 10
A vulnerability dashboard displays an EPSS probability of 0.10 and a percentile of 0.95. The response manager describes this as a 95% chance that the organization's server will be compromised within 30 days. What do those two values actually express?
Show answer & explanation
Correct answer: B - A 10% probability of observed in-the-wild exploitation over 30 days; a probability score higher than 95% of scored vulnerabilities.