
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 3
Advanced Persistent Threats (APTs) TIE Practice Questions (Page 2)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
42questions here
9free pages
6concepts
Questions 6–10
- 6
A threat intelligence analyst is reviewing logs and notices that a workstation in the finance department is making DNS queries to a domain that was registered only three days ago and has a very low reputation score. The workstation also established a persistent connection to an IP address in a country where the company has no business operations. Which two indicators of compromise (IoCs) are most directly highlighted by this observation?
Select an answer first - 7
A security operations center (SOC) is investigating a potential APT. They notice a series of failed login attempts from a single IP address, followed by a successful login from the same IP using a legitimate account. The account then accessed a large number of files on a file share. Which detection strategy would be most effective in identifying this as malicious activity?
Select an answer first - 8
A SOC analyst is reviewing a report from an EDR solution that flags a process running from a temporary directory with a known malicious file hash. The analyst also notices that the process is making HTTP requests to a domain that has been associated with a known APT group. Which two indicators of compromise (IoCs) are present in this scenario?
Select an answer first - 9
A security analyst at a mid-sized manufacturing firm notices a series of small, encrypted data transfers from a single engineering workstation to an external IP address over the past three months. The transfers occur every few days, always at 2:00 AM, and the workstation shows no signs of malware in standard scans. The analyst also finds that the workstation has been sending beacon-like signals to a domain registered three years ago that has no web content. Which combination of observations most strongly indicates an APT rather than a typical malware infection?
Select an answer first - 10
Which APT group is commonly associated with the Chinese government and has been observed targeting aerospace, technology, and government sectors for intellectual property theft?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.