
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 3
Advanced Persistent Threats (APTs) TIE Practice Questions (Page 1)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
42questions here
9free pages
6concepts
Questions 1–5
- 1
A threat intelligence analyst is comparing two APT groups. Group A has been active for five years, targets government and defense organizations, uses custom malware, and is believed to be state-sponsored. Group B has been active for two years, targets financial institutions, uses ransomware, and is believed to be financially motivated. The analyst must advise a defense contractor on which group poses the greater risk to their organization. Which consideration is most important in this risk assessment?
Select an answer first - 2
A security operations manager at a large enterprise is reviewing a year-long intrusion that was only discovered after a third-party threat intelligence report matched a domain used by the attackers. The attackers used a combination of spear-phishing, living-off-the-land binaries, and encrypted C2 traffic. The manager must now justify additional security investments to the board. Which argument best justifies the investment in threat hunting and behavioral analytics, given the characteristics of this intrusion?
Select an answer first - 3
Which well-known APT group is widely reported to be sponsored by the North Korean government and has been linked to cyber-espionage and financially motivated attacks?
Select an answer first - 4
A security team is reviewing the 2013 Target breach, where attackers gained access through a third-party HVAC vendor's credentials, then moved laterally to the POS system and exfiltrated payment card data. The team wants to apply lessons learned to their organization, which uses multiple third-party vendors with network access. Which combination of measures is most directly aligned with the lessons from this case study?
Select an answer first - 5
A company's security team has identified a sophisticated threat actor that has been silently collecting credentials and moving laterally for several months. The team wants to implement a strategy that focuses on proactively searching for signs of the attacker's presence rather than relying solely on automated alerts. Which approach best aligns with this goal?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.