Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 7Objective 3

Threat Prediction with Cyber Threat Intelligence CND Practice Questions (Page 2)

Part of the Risk and Threat Management domain, which makes up ~16% of our current practice bank.

57questions here
12free pages
10concepts

Questions 6–10

  1. 6expert · hard

    A security team has a SIEM and an EDR. They receive a threat feed with a mix of low-confidence and high-confidence IoCs. The team wants to minimize false positives while ensuring that high-confidence indicators are immediately blocked. Which approach best balances detection and operational impact?

    Select an answer first
  2. 7application · medium

    A security analyst at a mid-sized company needs to detect early signs of a new ransomware campaign that is targeting their industry. The analyst has limited budget and wants to supplement internal telemetry with external indicators. Which combination of sources would provide the most cost-effective and timely coverage?

    Select an answer first
  3. 8application · medium

    A company has identified a new zero-day vulnerability in a widely used software product. The security team wants to share this information with other organizations to help them protect themselves. Which action is most appropriate for responsible threat intelligence sharing?

    Select an answer first
  4. 9expert · hard

    A company has detected a new phishing campaign targeting their employees. They want to share this intelligence with other companies in their sector to prevent similar attacks. However, they are concerned about revealing internal email addresses and the specific lure used. What is the best way to share?

    Select an answer first
  5. 10expert · hard

    A company is part of an ISAC and also subscribes to a commercial threat feed. They have discovered a zero-day vulnerability in a vendor product used by many members. The company wants to share this information to help others, but is concerned about revealing their own exposure and tipping off attackers. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.