
EC-CouncilCertified Ethical Hacker
Domain 1Objective 8
Threat Intelligence and Incident Management CEH Practice Questions (Page 6)
Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)
60questions here
12free pages
12concepts
Questions 26–30
- 26
A threat intelligence team is building a collection plan for a new intelligence requirement about a specific malware family. The team has access to OSINT feeds, commercial feeds, internal logs, and dark web forums. The team has limited time and needs to produce actionable intelligence quickly. Which collection strategy is most efficient?
Select an answer first - 27
A security analyst is triaging two incidents: (1) a phishing email that was reported by a user but not clicked, and (2) a suspected data exfiltration from a database server. Which incident should be classified as higher severity and prioritized?
Select an answer first - 28
During a security incident, the on-call analyst discovers that the incident involves a critical server and requires expertise beyond their level. The incident response plan specifies that the incident commander should be notified for critical incidents. However, the incident commander is currently unavailable. What should the analyst do?
Select an answer first - 29
A threat intelligence analyst is evaluating sources for a new program. The analyst has access to a commercial feed that provides high-confidence indicators but is expensive, an OSINT feed that is free but has a high false-positive rate, and internal logs that are accurate but only reflect past activity. The analyst needs to support real-time blocking decisions. Which combination of sources is most appropriate?
Select an answer first - 30
A threat intelligence team has just completed a quarterly report on ransomware campaigns targeting the organization's sector. The report was distributed to executives and the SOC, but the team notices that the SOC has not adjusted its detection rules based on the new indicators. According to the threat intelligence lifecycle, which phase is most likely being neglected?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.