Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 1Objective 8

Threat Intelligence and Incident Management CEH Practice Questions (Page 9)

Part of the Information Security and Ethical Hacking Overview domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~16–27 in this domain), expect 2–3 from this objective — we provide 60 practice questions to prepare you well beyond it. (estimate)

60questions here
12free pages
12concepts

Questions 41–45

  1. 41expert · hard

    During an incident, the response team discovers that the attacker has established persistence via a scheduled task on multiple servers. The team has contained the immediate threat by isolating the affected servers. However, the business requires these servers to be back online within 24 hours. What should the team do to balance thorough eradication with the business deadline?

    Select an answer first
  2. 42expert · hard

    A threat intelligence analyst is correlating data from multiple feeds and notices that a specific IP address appears in a commercial feed as a C2 server, but the same IP is listed in an OSINT feed as a legitimate web server. The analyst must decide whether to block the IP. What is the most appropriate action?

    Select an answer first
  3. 43foundation · easy

    What is a common source of feedback for improving threat intelligence?

    Select an answer first
  4. 44application · medium

    A threat intelligence team has produced a report on a new phishing campaign targeting the finance department. The report includes IOCs and recommended actions. The team needs to ensure that the finance department's leadership understands the business impact, while the SOC needs the technical IOCs. What is the most effective dissemination approach?

    Select an answer first
  5. 45application · medium

    A threat intelligence analyst is setting up data collection for a new program. The analyst wants to collect data from internal sources, open-source intelligence, and commercial feeds. Which method is most appropriate for collecting data from internal sources?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.