
EC-CouncilCertified SOC Analyst
Domain 5Objective 1
Threat Intelligence CSA Practice Questions (Page 3)
Part of the Proactive Threat Detection domain, which makes up ~14% of our current practice bank.
51questions here
11free pages
10concepts
Questions 11–15
- 11
A SOC analyst is reviewing a threat intelligence report that describes a new attack campaign. The report includes the TTPs used by the attackers, the specific tools they employ, and the indicators of compromise. The analyst needs to determine if the organization is vulnerable to this campaign. Which type of intelligence is most useful for this assessment?
Select an answer first - 12
What is the role of TAXII in threat intelligence sharing?
Select an answer first - 13
A SOC team is establishing a threat intelligence program. They have limited resources and need to decide which sources to prioritize. The team has identified a commercial feed, an open-source feed, and internal telemetry. They want to maximize the value of their intelligence while minimizing the effort required to process it. What is the most effective strategy?
Select an answer first - 14
A SOC team is implementing a new threat intelligence program. After collecting data from various sources, they have identified a new phishing campaign targeting their industry. They need to ensure the intelligence is used to update detection rules and that the process is continuously improved. Which step of the threat intelligence lifecycle is most critical to ensure the program remains effective?
Select an answer first - 15
A SOC analyst is reviewing a threat intelligence report that includes a list of malicious IP addresses. The analyst wants to check if any of these IPs have been observed in the company's proxy logs. Which approach is most efficient?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.