
EC-CouncilSOC Essentials
Domain 7Objective 1
Threat Intelligence Sources, Types, and Lifecycle SCE Practice Questions (Page 3)
Part of the Threat Intelligence and Hunting domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
3concepts
Questions 11–15
- 11
A mid-sized company wants to build a threat intelligence program on a limited budget. The team has decided to use free OSINT feeds, but the SOC lead is concerned about the volume of false positives and the lack of context in these feeds. Which lifecycle phase should the team enhance to address this concern?
Select an answer first - 12
A SOC analyst is evaluating a new threat intelligence source. The source provides detailed reports on threat actor groups, including their motivations, targets, and TTPs, but does not provide any IOCs. The analyst wants to use this source to improve the team's detection capabilities. Which type of intelligence is this source providing, and how should the analyst use it?
Select an answer first - 13
A SOC analyst receives a report from a government CERT describing the tactics, techniques, and procedures (TTPs) of a nation-state actor targeting the energy sector. The analyst needs to use this information to update detection rules. Which type of threat intelligence does this report primarily represent?
Select an answer first - 14
A regional bank's SOC manager needs to brief the board of directors on emerging ransomware trends affecting the financial sector. The briefing must include high-level risk implications and recommended investment priorities, without technical jargon. Which type of threat intelligence should the SOC manager primarily use for this briefing?
Select an answer first - 15
A SOC analyst is investigating a phishing campaign targeting their organization. They need to find indicators of compromise (IOCs) such as malicious URLs and email subject lines. Which internal source would be most useful?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.