Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 7Objective 1

Threat Intelligence Sources, Types, and Lifecycle SCE Practice Questions (Page 2)

Part of the Threat Intelligence and Hunting domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
3concepts

Questions 6–10

  1. 6application · medium

    A SOC analyst is documenting a newly identified phishing campaign targeting the company's finance team. The analyst has already extracted the sender domains, subject lines, and payload hashes, and now needs to share this information with the incident response team so they can update email filters. At which phase of the threat intelligence lifecycle is the analyst working?

    Select an answer first
  2. 7expert · hard

    A SOC team is implementing a threat intelligence platform (TIP). The team has configured the TIP to automatically ingest OSINT feeds and commercial feeds. However, the team is overwhelmed by the volume of alerts generated by the OSINT feeds. The team lead wants to reduce the noise without losing the value of the OSINT data. Which lifecycle phase should the team adjust?

    Select an answer first
  3. 8application · easy

    A SOC team is implementing a threat intelligence program. They have defined their intelligence requirements and are now collecting data from multiple sources. According to the threat intelligence lifecycle, what should they do immediately after collection?

    Select an answer first
  4. 9expert · hard

    A SOC analyst is investigating an alert about a suspicious file. The analyst finds that the file's hash matches a known malware hash from a commercial feed, but the file also has a valid digital signature from a reputable software vendor. The analyst must decide whether to quarantine the file. Which type of threat intelligence should the analyst consult to make the best decision?

    Select an answer first
  5. 10foundation · easy

    In the threat intelligence lifecycle, which phase involves defining the intelligence requirements and identifying the specific questions the organization needs to answer?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.