
EC-CouncilSOC Essentials
Domain 7Objective 5
Leveraging Threat Intelligence for Hunting SCE Practice Questions (Page 6)
Part of the Threat Intelligence and Hunting domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
9concepts
Questions 26–30
- 26
A threat intelligence report indicates that a specific APT group has been using PowerShell to download and execute payloads from GitHub repositories. The SOC manager wants to proactively hunt for this activity in the environment. Which hypothesis would best guide the hunt?
Select an answer first - 27
What is the purpose of correlating threat intelligence with internal telemetry?
Select an answer first - 28
A SOC analyst is correlating internal telemetry with a threat intelligence feed. The feed contains a large number of IOCs, and the analyst finds that many internal hosts have communicated with these IOCs. However, the analyst suspects that many of these communications are false positives due to shared infrastructure. The analyst has limited time and must decide how to proceed. Which action is most effective?
Select an answer first - 29
How can threat hunting results refine threat intelligence for future hunts?
Select an answer first - 30
Which of the following is an example of enriching a threat intelligence finding?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.