
EC-CouncilSOC Essentials
Domain 7Objective 1
Threat Intelligence Sources, Types, and Lifecycle SCE Practice Questions (Page 6)
Part of the Threat Intelligence and Hunting domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
3concepts
Questions 26–30
- 26
A SOC team has completed the analysis phase of the threat intelligence lifecycle and produced a report on a new malware campaign. What is the next step in the lifecycle?
Select an answer first - 27
A SOC manager is reviewing the threat intelligence program's effectiveness. The manager notices that the team is spending too much time manually validating indicators from a free OSINT feed, and that the commercial feed is underutilized. The manager wants to optimize the workflow. Which change best addresses the imbalance?
Select an answer first - 28
A SOC team is overwhelmed by the volume of threat intelligence from multiple sources. They need to prioritize which intelligence to act on first. The team has a mature detection program but limited analyst time. Which approach is most effective?
Select an answer first - 29
A SOC analyst is documenting the sources of threat intelligence available to their organization. Which of the following correctly categorizes a public malware sandbox report as a threat intelligence source?
Select an answer first - 30
A SOC manager must decide how to allocate limited analyst time to consume threat intelligence. The team needs to improve detection of a specific APT group's techniques. Which type of intelligence should the team focus on to directly improve detection rules?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.